{"id":"GHSA-fg86-4c2r-7wxw","summary":"TorrentPier Deserialization of Untrusted Data vulnerability","details":"### Summary\n\nIn `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled cookies:\n\nhttps://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60\n\n### PoC\n\nOne can use [`phpggc`](https://github.com/ambionics/phpggc/) and the chain `Guzzle/FW1` to write PHP code to an arbitrary file, and execute commands on the system. For instance, the cookie `bb_t` will be deserialized when browsing to `viewforum.php`.","aliases":["CVE-2024-40624"],"modified":"2026-05-13T13:55:20.332759Z","published":"2024-07-15T17:48:26Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-07-15T17:48:26Z","nvd_published_at":"2024-07-15T20:15:04Z"},"references":[{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/security/advisories/GHSA-fg86-4c2r-7wxw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40624"},{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/commit/ed37e6e522f345f2b46147c6f53c1ab6dec1db9e"},{"type":"PACKAGE","url":"https://github.com/torrentpier/torrentpier"},{"type":"WEB","url":"https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60"}],"affected":[{"package":{"name":"torrentpier/torrentpier","ecosystem":"Packagist","purl":"pkg:composer/torrentpier/torrentpier"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.4"}]}],"versions":["2.3.0.4-beta","2.3.0.4-beta2","v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.3.0","v2.3.0.1","v2.3.0.2","v2.3.0.3","v2.3.1","v2.3.1-rc1","v2.4.0","v2.4.0-alpha1","v2.4.0-alpha2","v2.4.0-alpha3","v2.4.0-alpha4","v2.4.0-beta1","v2.4.0-beta2","v2.4.0-beta3","v2.4.0-beta4","v2.4.0-rc1","v2.4.0-rc2","v2.4.1","v2.4.2","v2.4.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.4.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-fg86-4c2r-7wxw/GHSA-fg86-4c2r-7wxw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}