CVE-2026-41570 | sebastianbergmann phpunit 12.5.21/13.1.5 INI Parser auto_prepend_file crlf injection (GHSA-qrr6-mg7r-m243 / Nessus ID 313605)
A vulnerability identified as critical has been detected in sebastianbergmann phpunit 12.5.21/13.1.5. Affected by this vulnerability is the function auto_prepend_file of the component INI Parser. Performing a manipulation results in crlf injection.
This vulnerability is known as CVE-2026-41570. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.