Vendor Phpunit Phpunit Src Util Php Eval-stdin.php Exploit [exclusive] -

Technical details (concise)

Action plan (recommended)

The root cause is deploying composer with the --dev flag or not using --no-dev in production. Many developers run composer install (which installs everything) on a live server. PHPUnit, being a require-dev dependency by default, ends up in the public web root. vendor phpunit phpunit src util php eval-stdin.php exploit

If you run composer install without --no-dev on a public server, you are effectively inviting attackers to execute any code they wish. The fix is simple: Use .gitignore for vendor/ on the build side, and never, ever let phpunit touch your production web root. being a require-dev dependency by default