{"id":"CVE-2024-51736","aliases":["GHSA-qq5c-677p-737q"],"url":"https://o3.security/vulnerability/CVE-2024-51736","summary":"Command execution hijack on Windows with Process class in symfony/process","details":"### Description\n\nOn Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking.\n\n### Resolution\n\nThe `Process` class now uses the absolute path to `cmd.exe`.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9) for branch 5.4.\n\n### Credits\n\nWe would like to thank Jordi Boggiano for reporting the issue and Nicolas Grekas for providing the fix.","published":"2024-11-06T20:51:38.536Z","modified":"2026-08-12T03:51:33.350765606Z","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},"epss":{"score":0.00426,"percentile":0.35342,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/process","fixedVersion":"5.4.46"},{"ecosystem":"Packagist","name":"symfony/process","fixedVersion":"6.4.14"},{"ecosystem":"Packagist","name":"symfony/process","fixedVersion":"7.1.7"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"5.4.46"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"6.4.14"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"7.1.7"}],"fix":{"url":"https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9","label":"symfony/symfony@18ecd03"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/51xxx/CVE-2024-51736.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-qq5c-677p-737q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51736"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/process/CVE-2024-51736.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2024-51736.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2024-51736"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:33.350765606Z"}}