Loading HuntDB...

GHSA-ggwg-cmwp-46r5

GitHub Security Advisory

yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Affected Packages

Packagist yiisoft/yii2
Affected versions: 0 (fixed in 2.0.52)

Related CVEs

Key Information

GHSA ID
GHSA-ggwg-cmwp-46r5
Published
April 10, 2025 3:31 AM
Last Modified
July 30, 2025 11:46 AM
CVSS Score
9.0 /10
Primary Ecosystem
Packagist
Primary Package
yiisoft/yii2
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.