CVE-2026-24765 | sebastianbergmann phpunit up to 8.5.51/9.6.32/10.5.61/11.5.49/12.5.7 cleanupForCoverage deserialization (GHSA-vvj3-c3rp-c85p / EUVD-2026-4725)
A vulnerability has been found in sebastianbergmann phpunit up to 8.5.51/9.6.32/10.5.61/11.5.49/12.5.7 and classified as problematic. The affected element is the function cleanupForCoverage. This manipulation causes deserialization.
The identification of this vulnerability is CVE-2026-24765. The attack can only be executed locally. There is no exploit available.
The affected component should be upgraded.