File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -18,7 +18,7 @@ class ArrayCast extends BaseCast
1818 public static function get ($ value , array $ params = []): array
1919 {
2020 if (is_string ($ value ) && (str_starts_with ($ value , 'a: ' ) || str_starts_with ($ value , 's: ' ))) {
21- $ value = unserialize ($ value );
21+ $ value = unserialize ($ value, [ ' allowed_classes ' => false ] );
2222 }
2323
2424 return (array ) $ value ;
Original file line number Diff line number Diff line change 1+ <?php
2+
3+ declare (strict_types=1 );
4+
5+ /**
6+ * This file is part of CodeIgniter 4 framework.
7+ *
8+ * (c) CodeIgniter Foundation <admin@codeigniter.com>
9+ *
10+ * For the full copyright and license information, please view
11+ * the LICENSE file that was distributed with this source code.
12+ */
13+
14+ namespace CodeIgniter \Entity \Cast ;
15+
16+ use CodeIgniter \Test \CIUnitTestCase ;
17+ use PHPUnit \Framework \Attributes \Group ;
18+ use stdClass ;
19+
20+ /**
21+ * @internal
22+ */
23+ #[Group('Others ' )]
24+ final class ArrayCastTest extends CIUnitTestCase
25+ {
26+ public function testGetPreventsObjectInjection (): void
27+ {
28+ $ payload = serialize ([new stdClass ()]);
29+
30+ $ result = ArrayCast::get ($ payload );
31+
32+ $ this ->assertIsArray ($ result );
33+ $ this ->assertInstanceOf ('__PHP_Incomplete_Class ' , $ result [0 ]);
34+ }
35+ }
You can’t perform that action at this time.
0 commit comments