Skip to content
CAI
Software that uses CAICheck a score

ambionics/phpggc

43.5

Weak · 19 September 2026

12.3k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a command-line tool and library for generating PHP object injection payloads, specifically targeting deserialization vulnerabilities in popular PHP frameworks and libraries. It provides a catalog of gadget chains that enable remote code execution, file manipulation, and other attacks by chaining existing class methods. The tool supports generating these payloads via CLI or programmatically, including the creation of polyglot PHAR files.

How it got here

2017–2019 — Gadget chain expansion and API refactoring

38 changes.

This period focused on significantly expanding the library's coverage by adding numerous Remote Code Execution, File Write, and other vulnerability chains for major PHP frameworks like Laravel, Symfony, Drupal, and Zend. Concurrently, the core architecture was refactored to support programmatic usage, introducing a structured API for PHAR generation, a new enhancement framework for payload modification, and a standardized invocation model for RCE chains.

2020–2022 — expanding gadget chain coverage

28 changes.

This period focused on significantly expanding the library's catalog of PHP gadget chains by adding exploitation vectors for a wide variety of popular frameworks and libraries, including MediaWiki, CodeIgniter, WordPress, and Symfony. The work involved implementing new Remote Code Execution, File Deletion, File Write, and File Read chains, while also refining existing entries to reflect updated vulnerability landscapes and behavioral changes.

2023–2024 — expansion of gadget chain coverage

29 changes.

This period focused on significantly expanding the library of PHP gadget chains across a wide range of popular frameworks and applications, including Symfony, Laravel, Drupal, and WordPress. New entries were added to support Remote Code Execution, File Deletion, File Write, SQL Injection, and Account Takeover attacks for specific version ranges. The work primarily involved identifying and implementing exploitation vectors for existing vulnerabilities in these ecosystems.

2025 — Expansion of PHP gadget chains

5 changes.

This period focused on expanding the PHPGGC framework by adding new Remote Code Execution (RCE) and SQL injection gadget chains for various popular PHP libraries and CMS platforms. Specific additions included chains for League/Plates, Drupal/PsySH, WordPress/Yoast SEO, and Sulu, targeting vulnerabilities such as unserialization flaws and authenticated SQL injection vectors.

Features

Add authenticated SQL injection gadget for MySQL

A new abstract gadget class, MySQLAuthenticatedSQLI, has been added to the SQLI gadget chain library. This class enables SQL injection payloads that require valid database credentials, accepting parameters for SQL query, host, database name, username, and password. It extends the existing SqlInjection base class and is designed for scenarios where authenticated access to the MySQL database is necessary to execute the injection.

lib/PHPGGC/GadgetChain/SQLI · high confidence

Added Bitrix RCE gadget chain for versions 17.x.x through 22.0.300

A new remote code execution (RCE) gadget chain has been added for the Bitrix framework, covering versions 17.x.x up to 22.0.300. This chain leverages the \\_\_destruct\ magic method within the \Bitrix\\Main\\ORM\\Data\\Result\ class, chaining through \Dictionary\, \Error\, \ItemAttributes\, \ResultIterator\, and \ArrayResult\ to execute arbitrary functions. The implementation includes the necessary PHP class stubs in \gadgets.php\ to define the structure of these objects and the generation logic in \chain.php\.

gadgetchains/Bitrix · high confidence

Added CakePHP RCE gadget chains for versions up to 3.9.6 and 4.2.3

New PHPGGC gadget chains for CakePHP have been added, covering two distinct remote code execution vectors. The first chain (RCE1) targets CakePHP versions up to 3.9.6 and utilizes the \\_\destruct\ vector via \Symfony\\Component\\Process\\Process\ to execute system commands. The second chain (RCE2) targets versions up to 4.2.3, also using the \\\_destruct\ vector but leveraging \Cake\\Database\\Statement\\CallbackStatement\ to invoke arbitrary PHP functions with specified parameters.

gadgetchains/CakePHP · high confidence

Added CodeIgniter 4 File Delete gadget chains

Added two new gadget chains (FD/1 and FD/2) for the CodeIgniter 4 framework that enable file deletion via the \_\_destruct vector. FD/1 targets CodeIgniter 4 versions \<= 4.3.6 and utilizes the RedisHandler, FileHandler, and MemcachedHandler classes. FD/2 targets CodeIgniter 4 versions \<= 4.3.7 and utilizes the Publisher class.

gadgetchains/CodeIgniter4/FD · high confidence

Added CodeIgniter 4 File Read chain targeting versions 4.0.0–4.3.6

A new file-read gadget chain (FR1) has been added for CodeIgniter 4, covering versions 4.0.0 through 4.3.6. This chain leverages the \_\_toString vector to trigger an include() call via the CodeIgniter\\View\\Cells\\Cell class, allowing remote path inclusion.

gadgetchains/CodeIgniter4/FR · high confidence

Added CodeIgniter 4 RCE gadget chain (versions 4.0.4–4.4.3)

A new remote code execution gadget chain has been added for CodeIgniter 4 versions 4.0.4 through 4.4.3. The chain exploits the \\_\_destruct\ method in \CodeIgniter\\Cache\\Handlers\\RedisHandler\, which instantiates \Faker\\ValidGenerator\ with a user-controlled function name and parameter, ultimately allowing arbitrary function calls via the \Faker\ library's \DefaultGenerator\.

gadgetchains/CodeIgniter4/RCE/3 · high confidence

Added CodeIgniter 4 RCE gadget chain via RedisHandler

A new remote code execution (RCE) vulnerability chain has been added for CodeIgniter 4 (specifically targeting version 4.0.2). This chain exploits the \\_\_destruct\ method of \CodeIgniter\\Cache\\Handlers\\RedisHandler\ to trigger arbitrary function calls. The implementation defines the necessary gadget classes (\RedisHandler\, \MemcachedHandler\, \Model\, \Validation\, \BaseBuilder\) to construct the exploitation payload.

gadgetchains/CodeIgniter4/RCE/1 · high confidence

Added CodeIgniter 4 RCE gadget chains for versions up to 4.2.10

New remote code execution (RCE) exploit chains have been added for CodeIgniter 4 (versions up to 4.1.3+ and 4.2.10+). These chains leverage deserialization vulnerabilities in the \\_\_destruct\ magic method, utilizing gadget paths through Predis, CodeIgniter Entity, Symfony Request, and Faker libraries to achieve arbitrary function execution.

gadgetchains/CodeIgniter4/RCE/5 · high confidence

Added Doctrine FW/2 gadget chain for PHP versions 2.3.0–2.8.5

Added a new file-write gadget chain targeting Doctrine versions 2.3.0 through 2.4.0 and 2.5.0 through 2.8.5. The chain exploits the \_\_destruct method of Doctrine's PSR-6 cache adapters to write arbitrary PHP code to a specified remote path, creating a side directory named '8a' in the same location as the target file.

gadgetchains/Doctrine/FW/2 · high confidence

Added Dompdf file deletion gadget chains

Added two new gadget chains for the Dompdf library that enable file deletion via the \_\_destruct vector. Chain 1 targets Dompdf versions 1.1.1 and newer, utilizing the \\Dompdf\\CPDF class, while Chain 2 targets versions older than 1.1.1, utilizing the \\Dompdf\\Adapter\\CPDF class. Both chains allow an attacker to specify a remote path that gets added to an image cache array, which is subsequently processed during object destruction to delete files.

gadgetchains/Dompdf, gadgetchains/SwiftMailer/FD · high confidence

Added Drupal 7 File Delete gadget chain for versions up to 7.78

A new file delete gadget chain (FD1) has been added for Drupal 7 versions 7.0 through 7.78. This chain exploits the \Archive\Tar\ destructor, which was hardened in Drupal 7.79, making this specific exploit vector ineffective in newer releases. The implementation includes the necessary PHP classes to generate the malicious payload targeting the \\\_destruct\ vector.

gadgetchains/Drupal7/FD · high confidence

Added Drupal 7 RCE gadget chain for versions 7.0.8 to 7.98

A new remote code execution gadget chain has been added for Drupal 7 versions 7.0.8 through 7.98. This chain exploits the \_\_destruct method of the SchemaCache class, allowing an attacker to execute arbitrary functions by posting a specific form\_build\_id to the system/ajax endpoint.

gadgetchains/Drupal7/RCE · high confidence

Added Drupal 7 SQL injection and SSRF gadget chains

Added PHPGGC gadget chains for Drupal 7 (versions \<= 7.101) that exploit the \\_\_destruct\ vector via \ThemeRegistry\ and \DatabaseStatementPrefetch\. The SQL injection chain allows execution of arbitrary SQL commands through PDO initialization commands or SQLite init commands, while the SSRF chain enables blind XXE attacks by loading external XML entities. These chains are linked to security advisory SA-CORE-2024-008.

gadgetchains/Drupal7/SQLI, gadgetchains/Drupal7/SSRF · high confidence

Added Drupal 9 RCE gadget chain (versions 8.9.6–9.5.10+)

A new remote code execution gadget chain has been added for Drupal versions 8.9.6 through 9.5.10 and later. This chain leverages the default inclusion of Guzzle and Laminas libraries, triggering a \\_\destruct()\ call that chains through \\\_toString()\ and \call\_user\_func\_array\ to execute arbitrary functions. The implementation includes the necessary PHPGGC chain definition and stubbed gadget classes for \FileCookieJar\, \RelativeStream\, \PumpStream\, \CachedStorage\, \MemoryStorage\, and \Container\.

(repo-wide) · high confidence

Added Drupal Account Takeover gadget chain for versions 8.x–11.x

A new gadget chain has been added to the Drupal Account Takeover (AT) category, targeting Drupal versions 8.0.0 through 10.2.10, 10.3.0 through 10.3.8, and 11.0.0 through 11.0.7. This chain exploits the \\_\_wakeup\ vector to update the email address and username of the administrator account (UID 1) to 'admin', enabling a password reset attack. The implementation includes the necessary PHP class stubs for \ViewExecutable\, \DisplayPluginCollection\, \DefaultDisplay\, \Update\, and \Condition\ to facilitate the exploit.

gadgetchains/Drupal/AT · high confidence

Added Drupal authenticated SQL injection and SSRF gadget chains

Added new PHPGGC gadget chains for Drupal (versions \>= 8.0.0 \< 10.2.11 and \>= 10.3.0 \< 10.3.9) that leverage the \\_\_wakeup\ vector. The SQLI1 chain enables authenticated SQL injection by exploiting \Drupal\\Core\\Url\ and \Drupal\\Core\\Database\\StatementPrefetch\ to execute arbitrary SQL via PDO initialization commands. The SSRF1 chain allows Server-Side Request Forgery by triggering blind XXE through \SimpleXMLElement\ parsing within the same gadget chain, which can be used to extract database credentials for the SQL injection attack.

gadgetchains/Drupal/SQLI · high confidence

Added Drupal/PsySH INFO1 gadget chain

A new gadget chain targeting Drupal installations with PsySH (bundled with Drush) has been added, affecting versions \>= v0.9.0 \< v0.12.6. This chain leverages the \\_\_wakeup\ vector to execute \phpinfo()\ via the \Drupal\\views\\ViewExecutable\ class, as documented in Drupal security advisory SA-CORE-2024-007. The implementation includes the necessary PHP class stubs for \ViewExecutable\, \DisplayPluginCollection\, \DefaultDisplay\, and \ExecutionClosure\ to facilitate the chain.

gadgetchains/Drupal/PsySH · high confidence

Added Guzzle RCE chain for versions 6.0.0–6.3.2

A new remote code execution gadget chain has been added for Guzzle versions 6.0.0 through 6.3.2. This chain exploits the deserialization of \GuzzleHttp\\Psr7\\FnStream\ to execute arbitrary functions, utilizing \GuzzleHttp\\HandlerStack\ as the vector. The implementation requires specifying a function name and parameter, and notes that the payload is limited because \FnStream\ cannot be deserialized after use.

(repo-wide) · high confidence

Added Joomla File Write gadget chain for versions 3.9.0–5.2.1

A new gadget chain has been added for Joomla versions 3.9.0 through 5.2.1, enabling file write attacks via the \\_\_destruct\ vector. The implementation leverages \Joomla\\CMS\\Log\\Logger\\FormattedtextLogger\ and \Joomla\\CMS\\Log\\LogEntry\ to write arbitrary data to a specified remote path, a vulnerability fixed in Joomla 5.2.2.

gadgetchains/Joomla · high confidence

Added Kohana 3.x File Read gadget chain

A new gadget chain for Kohana versions 3.\* has been added to the framework-specific chains. This chain exploits a File Read vulnerability via the \_\_toString vector, specifically leveraging the View class to include remote files.

gadgetchains/Kohana · high confidence

Added Laravel 5.1.\* RCE gadget chain via Swift\_KeyCache\_DiskKeyCache

A new remote code execution gadget chain has been added for Laravel versions 5.1.\*, exploiting the Swift\_KeyCache\DiskKeyCache class. This chain leverages the \\_destruct magic method to trigger arbitrary function calls, utilizing a chain of objects from the Faker and Mockery namespaces to facilitate the exploit.

gadgetchains/Laravel/RCE/21 · high confidence

Added Laravel 5.8.30 RCE gadget chain via Mockery EvalLoader

A new remote code execution gadget chain has been added for Laravel versions up to 5.8.30. This chain exploits the Mockery library (typically a dev dependency) to execute arbitrary PHP code via the \\_\_destruct\ vector, specifically leveraging the \Mockery\\Loader\\EvalLoader\ class.

gadgetchains/Laravel/RCE/5 · high confidence

Added Laravel Pail file deletion gadget chain

A new gadget chain has been added for the Laravel Pail plugin, enabling file deletion via the \_\_destruct vector. This chain leverages the PailCommand class to target a specified remote file path, requiring the Laravel Pail plugin to be present in the target environment.

gadgetchains/Laravel/FD · high confidence

Added Laravel RCE chain targeting versions 5.6 through 10.x

A new remote code execution gadget chain (RCE/19) has been added for Laravel, covering versions 5.6 up to 10.x. This chain exploits the \Illuminate\\Support\\Sleep\ class, which is instantiated with a user-controlled command string. The exploit leverages the \Laravel\\Prompts\\Terminal\ class to execute the command via the \restoreTty\ method during object destruction, allowing arbitrary command execution.

gadgetchains/Laravel/RCE/19 · high confidence

Added Laravel RCE gadget chain 17 for versions up to 10.31.0

A new remote code execution gadget chain (RCE17) has been added for Laravel versions up to 10.31.0. This chain exploits the \\_\_destruct\ method of \Illuminate\\Routing\\PendingSingletonResourceRegistration\ to trigger arbitrary function calls via the \Illuminate\\Database\\DatabaseManager\ class.

gadgetchains/Laravel/RCE/17 · high confidence

Added Laravel RCE gadget chain targeting versions 5.6.0 through 9.5.1+

A new remote code execution gadget chain has been added for Laravel applications, covering versions 5.6.0 up to 9.5.1 and later. This chain exploits the Monolog RotatingFileHandler class, which triggers a call to the RequiredIf validation rule, ultimately invoking the RequestGuard callback to execute arbitrary functions via call\_user\_func.

gadgetchains/Laravel/RCE/16 · high confidence

Added Laravel RCE gadget chain targeting versions 5.8.35, 7.0.0, and 9.3.10

A new remote code execution gadget chain has been added for Laravel applications, supporting versions 5.8.35, 7.0.0, and 9.3.10. The chain exploits the Monolog RollbarHandler to trigger arbitrary function calls via the \_\_destruct magic method. It utilizes a specific serialization path involving RouteServiceProvider, View Factory, Symfony Console Application, Cache Repository, and PhpOption LazyOption to achieve execution, with implementation details varying slightly between Laravel 5 and later versions.

gadgetchains/Doctrine/RCE/2, gadgetchains/Laravel/RCE/12, gadgetchains/Symfony/RCE/4 · high confidence

Added Laravel RCE gadget chains for versions 5.4.0–8.6.9+

Two new remote code execution gadget chains have been added for Laravel versions 5.4.0 through 8.6.9+, utilizing the \\_\_destruct\ vector. The first chain (RCE2) leverages \Illuminate\\Broadcasting\\PendingBroadcast\ and \Illuminate\\Events\\Dispatcher\ to execute arbitrary functions with parameters, while the second chain (RCE4) uses \Illuminate\\Broadcasting\\PendingBroadcast\ and \Illuminate\\Validation\\Validator\ to achieve similar function execution. Both chains are implemented as subclasses of the new \FunctionCall\ base class, allowing users to specify the target function and its arguments directly.

(repo-wide) · high confidence

Added Magento 1 SQL injection gadget chain

A new SQL injection gadget chain for Magento 1 (versions \<= 1.9.4.0) has been added to the tool. This chain exploits the \_\_destruct vector via the Credis\_Client and Mage\_Sales\_Model\_Order\_Payment\_Transaction classes, allowing users to execute arbitrary SQL queries through the generated payload.

gadgetchains/Magento/SQLI · high confidence

Added Magento 2 File Delete gadget chain (FD/2)

A new file deletion gadget chain for Magento 2 has been added, leveraging the \Magento\\RemoteStorage\\Model\\TmpFileCopier\ class. This chain triggers via the \\_\_destruct\ magic method and allows an attacker to delete arbitrary files specified by the \remote\_path\ parameter, affecting Magento 2 versions where this class is present.

gadgetchains/Magento2/FD/2 · high confidence

Added Magento Framework file-write gadget chain

A new gadget chain targeting Magento Framework versions up to 1.9.4.0 has been added, enabling file write via the \_\_destruct vector. The chain leverages Zend\_Memory\_Manager to trigger a sequence involving Varien\_Cache\_Backend\_Eaccelerator, Zend\_Log, and Zend\_CodeGenerator\_Php\_File, allowing an attacker to write arbitrary data to a specified remote path.

gadgetchains/Magento/FW · high confidence

Added MediaWiki gadget chains for RCE, file deletion, and file write

New gadget chains have been added to the MediaWiki gadgetchain module, enabling exploitation of specific PHP deserialization vectors in MediaWiki versions 1.21.0+ and earlier. The changes introduce a Remote Code Execution (RCE) chain targeting MediaWiki \<= 1.31.16 via the \Wikimedia\\ScopedCallback\ class, a File Deletion (FD) chain for MediaWiki 1.21.0+ leveraging \Wikimedia\\FileBackend\\FSFile\\TempFSFile\, and a File Write (FW) chain for MediaWiki 1.25.0+ utilizing \JakubOnderka\\PhpParallelLint\\FileWriter\ (or its \PHP\_Parallel\_Lint\ equivalent). These additions expand the library's coverage of MediaWiki-specific serialization vulnerabilities.

gadgetchains/Laminas, gadgetchains/MediaWiki · high confidence

Added Monolog 3.0.0–3.1.0+ File Write gadget chain

A new gadget chain targeting Monolog versions 3.0.0 through 3.1.0+ has been added to the Monolog/FileWrite category. This chain leverages the \_\_destruct vector via Monolog\\Handler\\GroupHandler to achieve file write capabilities, specifically designed for educational and authorized penetration testing scenarios.

gadgetchains/Monolog/FW · high confidence

Added Monolog 3.0.0–3.1.0+ RCE gadget chain

A new Remote Code Execution (RCE) exploit chain has been added for Monolog versions 3.0.0 through 3.1.0 and later. This entry defines a \\_\_destruct\ vector that leverages \Monolog\\Handler\\FingersCrossedHandler\ to execute arbitrary functions, including the necessary internal \FingersCrossedHandler\, \Level\ enum, and \LogRecord\ class definitions required to trigger the vulnerability.

(repo-wide) · high confidence

Added Monolog RCE chain targeting versions 3.0.0 to 3.1.0+

A new remote code execution gadget chain has been added for the Monolog library, specifically affecting versions 3.0.0 through 3.1.0 and later. This entry defines an exploitation path via the \\_\_destruct\ vector, utilizing \Monolog\\Handler\\GroupHandler\ and \BufferHandler\ to trigger arbitrary function calls. The implementation includes the necessary PHP object structures (\LogRecord\, \Level\ enum) to facilitate the attack within the specified version range.

(repo-wide) · high confidence

Added OpenCart file-write gadget chains for versions 3.0.0–4.0.2.3

Added PHPGGC gadget chain definitions for OpenCart that enable file-write attacks via the \_\_destruct vector. The changes introduce three distinct chains covering OpenCart versions 3.0.0.0 through 4.0.2.3+, utilizing different class structures (such as Twig\_Cache\_Filesystem vs. Twig\\Cache\\FilesystemCache) to target specific version ranges.

gadgetchains/OpenCart/FW · high confidence

Added PHP templates for generating new gadget chain structures

New template files (chain.php and gadgets.php) have been added to the templates directory to support the programmatic creation of new gadget chains. These templates provide a basic directory and file structure scaffold, allowing users to generate new chain definitions via the CLI tool, although this feature is currently undocumented and not fully tested.

templates · high confidence

Added PHP-CS-Fixer file deletion gadget chains

Added new gadget chain definitions for the PHP-CS-Fixer library (versions \<= 2.17.3) that enable file deletion via the \_\_destruct magic method. The changes introduce two distinct chains: one leveraging the PhpCsFixer\\FileRemoval class and another chaining through PhpCsFixer\\Linter\\ProcessLinter to trigger file removal, providing exploitation paths for this specific vulnerability.

gadgetchains/PHPCSFixer · high confidence

Added PHPExcel gadget chains for WordPress

Added six new Remote Code Execution (RCE) gadget chains for the PHPExcel library within WordPress environments (targeting versions up to 1.8.2 and WordPress \< 5.5.2). These chains, authored by erwan\lr, exploit the \\\_toString\ magic method via \PHPExcel\RichText\ and the \\\_destruct\ method via \PHPExcel\_CachedObjectStorage\_DiscISAM\ and \PHPExcel\_Shared\_XMLWriter\ to execute arbitrary functions.

gadgetchains/WordPress/PHPExcel · high confidence

Added PHPGGC gadget chain for League/Plates RCE

A new Remote Code Execution (RCE) gadget chain has been added for the League/Plates templating library (versions 3.5.0 to 3.6.0). This chain exploits the \\_\_toString\ magic method via a crafted object graph involving \League\\Plates\\Template\\Template\, \Engine\, \Functions\, and \Func\ classes to execute arbitrary functions, providing a new vector for security testing and analysis within the PHPGGC framework.

gadgetchains/Plates · high confidence

Added PHPSecLib RCE gadget chain for versions 2.0.0–2.0.34

A new Remote Code Execution (RCE) gadget chain has been added for the PHPSecLib library, covering versions 2.0.0 through 2.0.34. This chain exploits the \\_\_destruct\ magic method within the \phpseclib\\Crypt\\Base\ class, which is inherited by \AES\ and \TripleDES\. By instantiating \SSH1\ with a \TripleDES\ object, the chain triggers the vulnerable constructor logic in \Base\ to execute arbitrary PHP code via the \inline\_crypt\ property assignment.

gadgetchains/Horde, gadgetchains/PHPSecLib, gadgetchains/WordPress/P/EverestForms · high confidence

Added PHPWord File Delete gadget chain targeting versions \<= 1.1.0

A new gadget chain (FD/1) has been added for PHPWord, enabling file deletion via the \_\_destruct vector in versions up to approximately 1.1.0. This chain exploits the XMLWriter class, where the tempFileName attribute is utilized to target remote file paths, with support for varying attribute names (\_tempFileName, tempFile, tempFileName) depending on the specific version.

gadgetchains/PHPWord · high confidence

Added Phalcon \< 1.2.3 RCE gadget chain

A new remote code execution gadget chain has been added for Phalcon versions 1.2.2 and earlier, triggered via the \_\_wakeup magic method. This chain exploits the Phalcon logger to evaluate PHP code supplied in the POST data (php://input), requiring the allow\_url\_include setting to be enabled.

gadgetchains/Phalcon · high confidence

Added Phing File Delete gadget chain (2.6.0–3.0.0a3)

A new gadget chain for the Phing build tool has been added, covering versions 2.6.0 through 3.0.0a3. This chain leverages the \\_\_destruct\ vector via the \WikiPublishTask\ class to perform file deletion, contributing to the library's catalog of PHP object injection exploitation paths.

gadgetchains/Phing · high confidence

Added Pydio Guzzle RCE gadgetchain

Added a new remote code execution (RCE) gadgetchain for Pydio versions prior to 8.2.2, leveraging the Guzzle HTTP client's FnStream class. This chain exploits the \_\_toString magic method to trigger arbitrary function calls via the Pydio ShutdownScheduler, allowing attackers to execute system commands or PHP code.

gadgetchains/Pydio · high confidence

Added RCE chain targeting Symfony 3.4.x through 5.2.1

A new remote code execution gadget chain (RCE/8) has been added for the Symfony framework, covering versions 3.4.0 to 4.4.18 and 5.0.0 to 5.2.1. This chain exploits the \_\_destruct magic method, leveraging the Router, RewindableGenerator, and AliasConfigurator classes to execute arbitrary functions.

gadgetchains/Symfony/RCE/8 · high confidence

Added Smarty File Delete gadget chain

A new gadget chain for Smarty has been added to the library, enabling file deletion attacks via the \_\_destruct vector. This chain leverages the Smarty\_Internal\_Template class to trigger a call to unlink() on a remote path specified by the user, effectively allowing an attacker to delete arbitrary files on the server.

gadgetchains/Smarty/FD · high confidence

Added Sulu RCE gadget chains for versions 2.5.0 through 2.6.7+

Added three distinct PHP gadget chains (RCE1, RCE2, RCE3) to the Sulu gadgetchain module, enabling remote code execution via unserialization in Sulu CMS versions 2.5.0–2.6.7+. The chains target the \\_\_destruct\ vector using \React\\EventLoop\\ExtEvLoop\ and \Goodby\\CSV\\Export\\Standard\\Collection\\CallbackCollection\, with specific implementations provided for different version ranges: RCE1 covers 2.5.0–2.5.19 and 2.6.0–2.6.2; RCE2 covers 2.5.19+ and 2.6.3–2.6.6; and RCE3 covers 2.6.7+.

gadgetchains/Sulu · high confidence

Added SwiftMailer 6.0.0–6.3.0 file-read gadget chain

A new file-read gadget chain for SwiftMailer versions 6.0.0 through 6.3.0 has been added, allowing remote file contents to be read via the \_\_toString vector. The implementation leverages Swift\_EmbeddedFile and related SwiftMailer classes to construct the exploit payload.

gadgetchains/SwiftMailer/FR · high confidence

Added Symfony 1.x RCE chain for versions 1.2.0–1.2.12

A new remote code execution gadget chain has been added for Symfony 1.x versions 1.2.0 through 1.2.12. This chain exploits the \\_\_wakeup\ vulnerability in \sfPropelPlugin\ by chaining \PropelDateTime\, \sfOutputEscaperObjectDecorator\, and \sfCultureInfo\ objects to achieve arbitrary function execution, addressing previous initialization errors in earlier chain attempts.

gadgetchains/Symfony/RCE/14 · high confidence

Added Symfony 1.x RCE gadget chain for [CVE redacted]

Added a new gadget chain targeting Symfony versions 1.1.0 through 1.5.18, exploiting the Serializable interface in sfNamespacedParameterHolder to achieve remote code execution via the sfOutputEscaperArrayDecorator class, as documented in [CVE redacted].

gadgetchains/Symfony/RCE/16 · high confidence

Added Symfony 1.x RCE gadget chain via Creole ORM

A new remote code execution gadget chain has been added for Symfony versions 1.0.0 through 1.1.9. This chain leverages the Creole ORM to achieve RCE via the \_\_wakeup deserialization vector, utilizing the sfOutputEscaperArrayDecorator and MySQLiTableInfo classes.

gadgetchains/Symfony/RCE/15 · high confidence

Added Symfony 1.x RCE gadget chain via sfDoctrinePager

A new remote code execution gadget chain has been added for Symfony versions 1.2.0 through 1.2.12. This chain exploits the Serializable interface in sfDoctrinePager, which requires the sfDoctrinePlugin to be enabled, allowing an attacker to trigger arbitrary function calls through the sfOutputEscaperArrayDecorator.

gadgetchains/Symfony/RCE/13 · high confidence

Added Symfony File Delete gadget chain for versions 3.2.7–3.4.25 and 4.0.0–4.2.6

A new file deletion gadget chain (FD1) has been added for Symfony, targeting versions v3.2.7 through v3.4.25 and v4.0.0 through v4.2.6. This chain exploits the \_\_destruct method of Symfony\\Component\\Cache\\Adapter\\PhpFilesAdapter to trigger file deletion, providing a specific exploitation vector for these affected Symfony releases.

gadgetchains/Drupal/FD, gadgetchains/Grav, gadgetchains/Symfony/FD · high confidence

Added Symfony FileWrite gadget chains for versions 2.5.2 and 3.4

New gadget chains have been added to the Symfony/FW location, enabling file write attacks for two specific Symfony versions. The first chain (FW1) targets Symfony 2.5.2 and utilizes the DebugImport vector via the /\profiler/import page to create files in the webroot. The second chain (FW2) targets Symfony 3.4 and leverages the \\_destruct vector through the SymfonyTestsListenerTrait to achieve file writes.

gadgetchains/Symfony/FW · high confidence

Added Symfony RCE chain targeting versions 2.0.4 through 5.4.24

A new remote code execution gadget chain has been added for Symfony versions 2.0.4 to 5.4.24. This chain exploits the \_\_destruct method by chaining Symfony's ConstraintViolationList, SortableIterator, and AnonymousToken classes to achieve arbitrary function calls.

gadgetchains/Symfony/RCE/11 · high confidence

Added Symfony RCE gadget chain for versions 2.0.4–5.4.24 via \_\_toString

A new remote code execution gadget chain (RCE10) has been added for Symfony versions 2.0.4 through 5.4.24, utilizing the \_\toString magic method as the attack vector. This chain leverages Symfony\\Component\\BrowserKit\\Response and Symfony\\Component\\Finder\\Iterator\\SortableIterator to execute arbitrary functions, complementing the previously added RCE9 chain which targets versions 2.6.0–4.4.18 using the \\_destruct vector.

gadgetchains/Symfony/RCE/10 · high confidence

Added Symfony RCE gadget chain for versions v3.1.0 to v3.4.34

A new remote code execution gadget chain has been added for Symfony versions v3.1.0 through v3.4.34. This chain exploits the \_\_destruct method in Symfony's ApcuAdapter, allowing an attacker to execute arbitrary system commands via proc\_open() by controlling the constructor arguments.

gadgetchains/Symfony/RCE/1 · high confidence

Added Symfony RCE gadget chain targeting versions 3.4.x and 4.0.x-4.1.x

A new remote code execution (RCE) gadget chain has been added for Symfony versions v3.4.0-BETA4 through v3.4.49 and v4.0.0-BETA4 through v4.1.13. This chain exploits the \\_\_destruct\ method of \Symfony\\Component\\Routing\\Loader\\Configurator\\ImportConfigurator\ to trigger command execution via \proc\_open()\. The chain links several Symfony classes (\ImportConfigurator\, \RedisProxy\, \InstanceofConfigurator\, \Psr6Cache\, and \PhpArrayAdapter\) to achieve the final execution vector.

gadgetchains/Drupal/XXE, gadgetchains/Symfony/RCE/6 · high confidence

Added TCPDF file deletion gadget chains for versions \<= 6.3.5 and 6.2.26–6.9.1

New PHPGGC gadget chains have been added for the TCPDF library, enabling file deletion via the \\_\_destruct\ magic method. Two variants are provided: FD1 targets TCPDF versions \<= 6.3.5 by exploiting the \imagekeys\ array, while FD2 targets versions 6.2.26 through 6.9.1 by leveraging both \file\_id\ and \imagekeys\, allowing path traversal outside \/tmp\ via a \/tmp/..\ prefix. These chains allow users to generate payloads that delete arbitrary files when a crafted TCPDF object is destroyed.

gadgetchains/TCPDF · high confidence

Added ThinkPHP 5.0 file-write gadget chains

Added new gadget chains for ThinkPHP versions 5.0.0–5.0.24 that enable file-write via the \_\_destruct vector. The chains leverage the think\\console\\Output and think\\cache\\driver\\Memcached classes to write arbitrary data to a remote path (which is hashed to a hex filename), supporting payloads up to 100,000 bytes.

gadgetchains/ThinkPHP/FW · high confidence

Added ThinkPHP 5.1.x-5.2.x RCE gadget chain

Added a new Remote Code Execution (RCE) gadget chain targeting ThinkPHP versions 5.1.x through 5.2.x. This chain leverages the \\_\_destruct\ vector in \think\\process\\pipes\\Windows\ to trigger arbitrary system command execution via the \think\\model\\Pivot\ class, specifically allowing the execution of the \system()\ function.

gadgetchains/ThinkPHP/RCE/1 · high confidence

Added ThinkPHP RCE gadget chains for versions up to 6.0.1

Added two new remote code execution (RCE) gadget chains targeting ThinkPHP versions up to 6.0.1+. The first chain (RCE3) leverages the \_\destruct vector via League\\Flysystem classes to trigger arbitrary function calls. The second chain (RCE4) also uses the \\_destruct vector but exploits the think\\model\\Pivot class and its associated traits to achieve the same outcome. These additions expand the tool's coverage for detecting and exploiting ThinkPHP RCE vulnerabilities.

gadgetchains/ThinkPHP/RCE/3, gadgetchains/ThinkPHP/RCE/4 · high confidence

Added Typo3 File Deletion gadget chain

A new gadget chain has been added for Typo3 versions 4.5.35 through 10.4.1, enabling file deletion via the \\_\_destruct\ vector in \TYPO3\\CMS\\Extensionmanager\\Controller\\UploadExtensionFileController\. This addition allows users to exploit this specific vulnerability to remove files, subject to system permissions.

gadgetchains/Typo3 · high confidence

Added WooCommerce RCE gadgetchain for versions \<=3.4.0

A new remote code execution gadgetchain has been added for WooCommerce versions up to 3.4.0 (and WordPress versions below 5.5.2). This chain leverages the \\_\_destruct\ vector via \WC\_Logger\ to execute arbitrary functions with specified parameters, providing a specific exploitation path for older WooCommerce installations.

gadgetchains/WordPress/P/WooCommerce/RCE/2 · high confidence

Added WordPress Core Gadget Chain RCE (RCE1)

A new remote code execution gadget chain (RCE1) has been added for WordPress Core versions up to 6.3.1. This chain exploits the \\_\_toString\ vector by leveraging the \WpOrg\\Requests\ library's \Hooks\ and \Session\ classes to trigger arbitrary function calls during HTTP request processing, specifically targeting the block registration system via \WP\_Theme\ and \WP\_Block\_List\.

gadgetchains/WordPress/RCE/1 · high confidence

Added WordPress Dompdf RCE gadget chains

New Remote Code Execution (RCE) gadget chains have been added for the WordPress Dompdf library, covering versions 0.7.0 through 0.8.5+ on WordPress versions prior to 5.5.2. These entries define exploitation paths via the \\_\_destruct\ vector in the \Dompdf\\Adapter\\CPDF\ class, allowing arbitrary function calls through the \Requests\_Utility\_FilteredIterator\. The changes include specific chain definitions for different Dompdf minor versions (0.7.0–0.8.4 and 0.8.5+) and corresponding gadget class definitions that model the protected or private \\_image\_cache\ property behavior.

gadgetchains/WordPress/Dompdf, gadgetchains/WordPress/Guzzle · high confidence

Added Yii 1.1.20 RCE gadget chain via \_\_destruct

A new remote code execution gadget chain has been added for Yii version 1.1.20, exploiting the \_\_destruct magic method. The chain constructs a payload using WikiPublishTask, which triggers a sequence involving Prophecy\\Argument\\Token\\ExactValueToken and PHPUnit\_Extensions\_Selenium2TestCase\_Session to achieve arbitrary function execution.

gadgetchains/Yii/RCE/2 · high confidence

Added Yii RCE gadget chain targeting version 1.1.20

A new Remote Code Execution (RCE) gadget chain has been added for the Yii framework (specifically targeting version 1.1.20). This chain exploits the \\_\_wakeup\ vector by chaining \CDbCriteria\, \CMapIterator\, and \CFileCache\ objects to execute arbitrary functions via the \data://\ wrapper, requiring \allow\_url\_fopen\ to be enabled.

gadgetchains/Yii/RCE/1 · high confidence

Added Yii2 RCE gadget chains for versions \< 2.0.38

Added two new remote code execution gadget chains for the Yii2 framework (versions prior to 2.0.38) to exploit [CVE redacted]. The first chain (RCE1) allows execution of arbitrary functions via call\_user\_func, while the second chain (RCE2) enables execution of arbitrary PHP code through eval(). These additions expand the available exploitation paths for this specific vulnerability.

gadgetchains/Spiral, gadgetchains/Yii2 · high confidence

Added Yoast SEO File Write gadget chain (FW1)

Added a new file-write gadget chain for WordPress Yoast SEO versions 19.0 through 24.9+, which leverages the \_\_destruct vector via the YoastSEO\_Vendor\\GuzzleHttp\\Cookie\\FileCookieJar class to write arbitrary data to a remote path.

gadgetchains/WordPress/P/YoastSeo · high confidence

Added Zend Framework 1 RCE chain via Zend\_Form

Added a new gadget chain targeting Zend Framework 1 versions 1.11.12 through 1.12.20, exploiting the Zend\_Form component to achieve remote code execution. The implementation leverages Zend\_Cache\_Frontend\_Function and Zend\_Form\_Decorator\_Form to trigger arbitrary function calls, requiring the presence of the zend-cache component.

gadgetchains/ZendFramework/RCE/2 · high confidence

Added Zend Framework 1 RCE gadget chain (versions \<= 1.12.20)

A new remote code execution gadget chain has been added for Zend Framework versions 1.12.20 and earlier. This chain exploits the deprecated 'e' modifier in \preg\replace\, which allows arbitrary code execution via the \\\_destruct\ magic method. The implementation constructs a payload using \Zend\_Log\, \Zend\_Log\_Writer\_Mail\, \Zend\_Layout\, and \Zend\_Filter\_PregReplace\ classes to trigger the vulnerability.

gadgetchains/ZendFramework/RCE/1, gadgetchains/ZendFramework/RCE/4, gadgetchains/ZendFramework/RCE/5 · high confidence

Added Zend Framework 1 file deletion chain

A new gadget chain has been added for Zend Framework 1 (versions \<= 1.12.20) that enables file deletion via the \_\_destruct vector. This change introduces a new chain definition and the corresponding Zend\_Http\_Response\_Stream gadget class, allowing the tool to generate payloads that delete remote files specified by the user.

gadgetchains/ZendFramework/FD · high confidence

Added Zend Framework 2 RCE chain targeting versions 2.0.1 and later

A new remote code execution gadget chain has been added for Zend Framework 2 (versions 2.0.1 and above). This chain exploits the \\_\_destruct\ method in \Zend\\Log\\Logger\ to trigger arbitrary function calls, utilizing a sequence of objects including \Zend\\Log\\Writer\\Mail\, \Zend\\Tag\\Cloud\, \Zend\\Escaper\\Escaper\, and \Zend\\Json\\Expr\ to achieve execution.

gadgetchains/ZendFramework/RCE/3 · high confidence

Added and updated SwiftMailer file-write gadget chains

New file-write gadget chains for SwiftMailer versions 3 (v5.0.1) and 4 (v4.0.0+) have been added, utilizing the \_\toString and \\_destruct vectors respectively to write arbitrary data to remote paths. The existing chains for versions 1 (v5.1.0–5.4.8) and 2 (v6.0.0–6.0.1) were updated to standardize property visibility to static and rename the preprocessing method to process\_parameters, while maintaining the necessary line-ending normalization for DomainKey signing.

gadgetchains/SwiftMailer/FW · high confidence

Added payload testing and diagnosis utilities

The library now includes two new diagnostic scripts: \lib/diagnose\_payload.php\ to inspect serialized payloads for undefined classes, and \lib/test\payload.php\ to execute payloads against specific vectors (such as PHAR, \\toString, \\destruct, or \\_wakeup) by loading the application's autoloader. These tools allow users to validate and debug generated gadget chains before deployment.

lib · high confidence

Added phpThumb file deletion gadget chain for versions \<= v1.7.22

A new gadget chain has been added for the phpThumb library, specifically targeting versions up to v1.7.22. This chain exploits a file deletion vulnerability triggered via the \\_\_destruct\ magic method, allowing an attacker to delete arbitrary files specified in the \tempFilesToDelete\ property of the \phpthumb\ class. The vulnerability was fixed in upstream pull request \#226.

gadgetchains/phpThumb · high confidence

Added vBulletin RCE1 gadget chain

A new remote code execution gadget chain (RCE1) for vBulletin versions 5.6.9 and later has been added. This chain leverages the \\_\_destruct\ vector and extends the existing Monolog RCE1 pattern by introducing a \googlelogin\_vendor\_autoload\ class to facilitate the exploit.

gadgetchains/vBulletin · high confidence

Dockerized distribution and updated CLI shebang

The tool is now available as a Docker image (Dockerfile) based on PHP 8.1 Alpine, which bundles the necessary dependencies (Python 3, Composer) and configures the environment to allow PHAR generation by setting phar.readonly=0. The main phpggc executable's shebang has been updated to use env -S to enforce this setting at runtime, and the script now exits with code 1 on errors. Additionally, a new test-gc-compatibility.py script was added to allow users to test gadget chains against specific versions of Composer packages, and the Apache 2.0 License file was added to the repository.

(repo-wide) · high confidence

New Laravel RCE chain (RCE18) via PHPUnit MockTrait

Added a new remote code execution gadget chain for Laravel versions up to 10.31.0. This chain exploits the PHPUnit MockTrait class to execute arbitrary PHP code via eval(), requiring PHPUnit to be present in the require-dev dependencies.

gadgetchains/Laravel/RCE/18 · high confidence

New Laravel RCE gadget chain (RCE20) added

A new Remote Code Execution gadget chain, identified as RCE20, has been added for Laravel versions 5.6 through 10.x. This chain exploits the \_\_destruct magic method via the Illuminate\\Routing\\PendingResourceRegistration class to execute arbitrary functions, providing a new vector for testing Laravel application security.

gadgetchains/Laravel/RCE/20 · high confidence

New Magento 2 arbitrary file deletion chain via RemoteStorage

Added a new gadget chain (FD/1) for Magento 2 that enables arbitrary file deletion within the installation directory. The chain leverages the \\_\_destruct\ vector in \Magento\\RemoteStorage\\Plugin\\Image\, which utilizes the \Magento\\Framework\\Filesystem\\Directory\\Write\ class to remove specified files or directories.

gadgetchains/Magento2/FD/1 · high confidence

New RCE gadget chain for YetAnotherStarsRating plugin

Added a new remote code execution (RCE) gadget chain targeting the YetAnotherStarsRating WordPress plugin (versions \<= 1.8.6 on WordPress \< 5.5.2). The chain exploits the \\_\_destruct\ magic method via the \yasr\_visitor\_vote\_cookie\ cookie, allowing an attacker to execute arbitrary PHP functions by manipulating the cookie payload on a page containing the plugin's visitor rating shortcode.

gadgetchains/WordPress/P/EmailSubscribers, gadgetchains/WordPress/P/YetAnotherStarsRating · high confidence

New RCE gadget chain subclasses for command execution, PHP code, and function calls

The RCE gadget chain module now includes three new abstract classes—Command, FunctionCall, and PHPCode—to better organize remote code execution payloads by their specific execution method. Command chains allow specifying a shell command, FunctionCall chains execute a PHP function with a single argument, and PHPCode chains inject arbitrary PHP code. This refactoring provides more granular control over the parameters passed to the gadget chain, improving clarity and usability for users generating these specific types of exploits.

lib/PHPGGC/GadgetChain/RCE · high confidence

New enhancement framework with built-in payload modifiers

The library introduces a new extensible enhancement system in lib/PHPGGC/Enhancement, allowing serialized payloads to be modified before generation. This includes built-in enhancements: ASCIIStrings (converts non-ASCII characters to hex using the 'S' format), FastDestruct (ensures \_\_destruct is called immediately after unserialize), PlusNumbers (adds '+' prefixes to integers/floats for PHP 7.2+ compatibility), PublicProperties (strips null-byte prefixes from protected/private properties to reduce payload size and avoid transmission issues), and Wrapper (allows custom user-defined scripts to modify parameters, objects, or serialized data).

lib/PHPGGC/Enhancement · high confidence

Programmatic PHAR generation with polyglot JPEG support

The library now exposes a structured, object-oriented API for generating PHAR archives programmatically, introducing a base Format class with specific implementations for PHAR, TAR, and ZIP formats. This refactoring allows developers to instantiate and configure formatters directly in PHP scripts rather than relying solely on command-line tools. A key capability added is the ability to generate polyglot files that are valid both as PHAR archives and JPEG images; the Tar formatter now handles this by embedding the PHAR data within a JPEG structure, ensuring the resulting file is detected as a JPEG by libmagic while remaining a valid PHAR for PHP execution.

lib/PHPGGC/Phar · high confidence

Behavioural changes

Added PHPExcel file deletion gadget chains

Added four new gadget chains for the PHPExcel library that leverage the \_\_destruct method to delete arbitrary files. The chains target PHPExcel versions 1.8.1 and earlier, as well as 1.8.2 and later, utilizing the PHPExcel\_CachedObjectStorage\_DiscISAM and PHPExcel\_Shared\_XMLWriter classes to perform the deletion.

gadgetchains/PHPExcel · high confidence

Added Silverstripe File Deletion gadget chain (v3.5.5–5.3.0+)

A new gadget chain has been added for Silverstripe versions 3.5.5 through 5.3.0+, enabling file deletion via the \\_\_destruct\ vector. The chain leverages the \SilverStripe\\Assets\\InterventionBackend\ class, which stores a user-controlled \tempPath\ that is subsequently deleted during object destruction.

gadgetchains/Silverstripe · high confidence

Added file deletion gadget chain for Snappy \<= 1.4.2

A new gadget chain targeting the KnpSnappyImage class has been added to the Snappy gadgetchains collection, specifically affecting versions up to approximately 1.4.2. This chain exploits the \_\_destruct method to trigger file deletion by manipulating the temporaryFiles array, allowing an attacker to remove arbitrary files depending on system permissions.

gadgetchains/Snappy · high confidence

Adds documentation and gadget chain for WordPress Requests\_Utility\_FilteredIterator

The generic WordPress gadget library now includes a new \gadgets.php\ file that documents how WordPress processes query variables and details the \Requests\_Utility\_FilteredIterator\ gadget chain. This entry notes that the vulnerability was introduced in WordPress 4.6 via the Requests library integration and was patched in WordPress 5.5.2, while explicitly listing which 5.x and 4.x versions remain vulnerable. It also provides the PHP class definition for the gadget to facilitate exploitation against unpatched systems.

gadgetchains/WordPress/generic · high confidence

Doctrine/FW1 gadget chain refined for robustness and clarity

The Doctrine/FW1 gadget chain has been updated to improve reliability and maintainability. The chain now correctly handles file paths that lack an extension, preventing potential errors during the file-write operation. Additionally, the author attribution has been corrected to 'cfreal', and the metadata definitions within the chain have been streamlined by removing unused properties, resulting in a more concise and readable exploit structure.

gadgetchains/Doctrine/FW/1 · high confidence

Guzzle FileWrite chain updated to support versions 4.0.0-rc.2 through 7.5.0+

The Guzzle FileWrite gadget chain definition has been updated to cover a significantly broader range of Guzzle versions, now supporting 4.0.0-rc.2 up to 7.5.0 and beyond. This change expands the applicability of the vulnerability chain, allowing it to be exploited against older and newer releases of the Guzzle HTTP client library than previously supported.

gadgetchains/Guzzle/FW · high confidence

Monolog RCE 2 now accepts function and parameter arguments with updated version support

The Monolog RCE 2 gadget chain has been refactored to accept a specific function name and its parameters instead of raw PHP code, changing the invocation from passing a code string to passing a function and a parameter. This change aligns with a broader shift in the tool's RCE chains to use function/parameter pairs. Additionally, the supported Monolog version range has been updated to 1.4.1 through 2.7.0+, and the internal gadget definitions have been adjusted to explicitly declare the socket property and modify the BufferHandler constructor logic.

gadgetchains/Monolog/RCE/2 · high confidence

Monolog RCE gadget chains updated with new versions and parameterized execution

The Monolog RCE gadget chains have been updated to support newer Monolog versions (e.g., RCE1 now targets 1.4.1–1.6.0 and 1.17.2–2.7.0+) and a new RCE4 chain has been added for Monolog \<= 2.4.4+ targeting Debian-based distributions with exim4. Additionally, the RCE1 chain's execution model has changed from accepting raw PHP code to accepting a function name and a single parameter, allowing for more flexible command execution via the SyslogUdpHandler and BufferHandler chain.

gadgetchains/Monolog/RCE/1 · high confidence

RCE gadget chains now accept function and parameter arguments instead of raw code

The Laravel and Slim RCE gadget chains have been updated to use a new invocation model where users specify a target function and its argument separately, rather than providing a raw code string. For example, the previous usage pattern \./phpggc something/rce1 'system("id")'\ is replaced by \./phpggc something/rce1 system id\. This change aligns the chains with the new \FunctionCall\ base class, which binds specific parameters to the payload generation, making the tool more structured and programmatically usable.

gadgetchains/Laravel/RCE/1, gadgetchains/Slim · high confidence

Refactored GadgetChain base classes to support programmatic use and new vulnerability types

The GadgetChain library has been refactored to support a wider range of vulnerability types and programmatic usage. New abstract base classes have been added for Account Takeover (AT), File Delete (FD), File Include (FI), PHP Info (INFO), Server-Side Request Forgery (SSRF), SQL Injection (SQLI), and XML External Entity (XXE) attacks. Existing classes for File Read (FR), File Write (FW), and Remote Code Execution (RCE) have been updated to use static type identifiers and descriptions, and now include built-in test infrastructure (setup, confirmation, and cleanup) to automate payload verification. Specifically, the RCE class no longer accepts raw code directly but relies on subclasses for specific execution methods, while File Write and File Read have been adjusted to handle local file paths without the file:// wrapper prefix.

lib/PHPGGC/GadgetChain · high confidence

Refactored GadgetChain class for programmatic use and improved CLI info display

The core GadgetChain class has been refactored to support programmatic usage, introducing new process\\ methods (process\_parameters, process\_object, process\_serialized) that allow users to hook into the generation pipeline at specific stages. Additionally, class properties such as type, version, and author have been changed from instance variables to static properties, and the CLI info output now correctly displays the gadget type by accessing these static properties, fixing a previous bug where the type was not shown.

lib/PHPGGC · high confidence

Smarty gadget chain updated to SSRF vector

The Smarty gadget chain has been reclassified from XXE to SSRF. The new implementation leverages the Smarty\_Template\_Cached class to trigger a Server-Side Request Forgery via SoapClient, reflecting the fact that the original XXE vector is no longer effective on recent PHP versions.

gadgetchains/Smarty/SSRF · high confidence

Updated CodeIgniter 4 RCE chain for versions 4.0.0-rc.4 through 4.3.6

The RCE gadget chain for CodeIgniter 4 has been updated to target versions 4.0.0-rc.4 through 4.3.6. This change replaces the previous chain with a new exploitation vector that utilizes the \CodeIgniter\\Cache\\Handlers\\RedisHandler\ class, chaining through \MemcachedHandler\, \Model\, and \Validation\ to achieve remote code execution via the \\_\_destruct\ magic method.

gadgetchains/CodeIgniter4/RCE/2 · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 43.

Lenses

  • Code Health 97
  • Architecture 100
  • Maturity 52
  • Readiness 12
  • Security 86

Changes since last survey

  • 300 commits — 278 feature/other, 22 fixes

By area

  • (repo) — 80 commits
  • (root) — 36 commits
  • gadgetchains/Laravel — 25 commits
  • lib/PHPGGC — 23 commits
  • gadgetchains/Symfony — 22 commits
  • gadgetchains/CodeIgniter4 — 13 commits
  • gadgetchains/Drupal — 10 commits
  • gadgetchains/WordPress — 10 commits
  • lib/PHPGGC.php — 9 commits
  • gadgetchains/Doctrine — 8 commits
  • gadgetchains/OpenCart — 8 commits
  • gadgetchains/Drupal9 — 6 commits
  • gadgetchains/SwiftMailer — 6 commits
  • gadgetchains/Drupal7 — 5 commits
  • gadgetchains/Magento2 — 5 commits
  • gadgetchains/TCPDF — 5 commits
  • gadgetchains/MediaWiki — 4 commits
  • gadgetchains/Snappy — 2 commits
  • gadgetchains/Spiral — 2 commits
  • gadgetchains/Sulu — 2 commits

Notable commits

  • fix: Codestyle fix on cyanM0un gadgets as usual
  • fix: Fixed a bug where php could be ran without parameters, resulting in a hang. Also, typo.
  • fix: Fixed codestyle and informations for the new Symfony/RCE* plugins.
  • fix: Fixed information and codestyle.
  • fix: Fixed information and codestyle.
  • fix: Fixed missing $parameters for RCE/PHPCode
  • fix: Fixed process_parameters() prototype in Laminas/FW1 to validate strict standards
  • fix: Fixed the namespace for WordPress/RCE1
  • fix: Fixed version for Drupal7/FD1
  • fix: Fixed version for Drupal7/RCE1
  • fix: Fixed version for WP/RCE1
  • fix: Fixed version for WP/RCE2
  • fix: Fixed versions
  • fix: Fixed versions
  • fix: Fixed versions for Symfony/RCE10
  • fix: Symfony/RCE16: fixed codestyle
  • fix: fix deprecation in the Drupal code; now the gadget is hopefully db-engine agnostic
  • fix: fix namespace of chain
  • fix: fix param order
  • fix: fix version details for RCE/1
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ambionics/phpggc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f8aebde3a1abb88b02042fd12a71b4c61d6cfe2c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.