From 7288dfc620230ca117cda353f5bf7ae45453b4bd Mon Sep 17 00:00:00 2001 From: Brown Date: Mon, 29 Jun 2020 17:54:47 -0400 Subject: [PATCH] Fix #3715 - unserialize is a taint sink --- src/Psalm/Internal/InternalTaintSinkMap.php | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/Psalm/Internal/InternalTaintSinkMap.php b/src/Psalm/Internal/InternalTaintSinkMap.php index b67692788..e2acd5afd 100644 --- a/src/Psalm/Internal/InternalTaintSinkMap.php +++ b/src/Psalm/Internal/InternalTaintSinkMap.php @@ -8,6 +8,7 @@ return [ 'file_put_contents' => [['shell']], 'fopen' => [['shell']], 'header' => [['text']], +'igbinary_unserialize' => [['text']], 'ldap_search' => [['text']], 'mysqli_query' => [[], ['sql']], 'passthru' => [['shell']], @@ -19,4 +20,5 @@ return [ 'setcookie' => [['text'], ['text']], 'shell_exec' => [['shell']], 'system' => [['shell']], +'unserialize' => [['text']], ];