Improper Input Validation Affecting october/october package, versions >=4.3.0, <4.3.5


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-OCTOBEROCTOBER-20186846
  • published28 Sept 2026
  • disclosed14 Sept 2026
  • creditUnknown

Introduced: 14 Sep 2026

New CVE NOT AVAILABLE CWE-20  (opens in a new tab)

How to fix?

Upgrade october/october to version 4.3.5 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation via the ResizeImageItem::fromObject process. An attacker can cause metadata deserialization and potentially execute arbitrary code by supplying a crafted phar:// path as untrusted input to the |resize filter or the ResizeImages::resize() API. This is only exploitable if a template author or backend configuration passes untrusted input into these image resizing functions without proper validation.

Workaround

This vulnerability can be mitigated by auditing template code and backend widget configuration for uses of the |resize filter (or direct ResizeImages::resize() calls) that accept untrusted string input, and validating that the scheme is http or https before passing it in.

References

CVSS Base Scores

version 4.0
version 3.1