CVE-2026-46420 (matched: php)

  • Thursday, 20th August, 2026
  • 22:07pm

A security flaw has been found in setup-php, a popular tool used to configure PHP for projects that run automated tasks via GitHub Actions (the automated workflow system for GitHub-hosted projects). Versions of this tool from 2.25.0 up to (but not including) 2.37.1 have a vulnerability that could let unauthorized people run arbitrary commands on the servers that execute your project's automated workflows, under specific conditions.

The issue occurs because the tool pulls PHP

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-46420

« Back