Skip to content

UnserializeExploits ​

error on by default

Group: Security · PhpStorm name: UnserializeExploitsInspection

unserialize() on attacker-controlled data can instantiate arbitrary classes (PHP object injection). Report calls whose input can be traced to request data or raw decoders, and — on PHP 7+ — calls that do not restrict the allowed classes.

Example ​

At PHP 5.6:

php
<?php
class Inbox
{
    public function load($path)
    {
        $data = file_get_contents($path);
        $data = gzinflate($data);
        return unserialize($data);
    }

    public function fromRequest()
    {
        $packed = $_POST['state']['blob'];
        $packed = $_COOKIE['state'];
        return unserialize($packed);
    }

    public function fromSession()
    {
        return unserialize($_SESSION['cart']);
    }

    public function permissive($s)
    {
        return unserialize($s, TRUE);
    }
}

Reported:

  • line 8: Untrusted data may reach unserialize() via: file_get_contents(...).
  • line 15: Untrusted data may reach unserialize() via: $_COOKIE, $_POST.
  • line 25: Restrict the classes unserialize() may create via its second argument.

Configure ​

In custos.json:

json
{
  "rules": {
    "UnserializeExploits": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore UnserializeExploits

/**
 * @noinspection UnserializeExploitsInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.