Back

CRITICAL

Xdebug Remote Debugger Unauthenticated OS Command Execution

Published Jul 23, 2025

Description

An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugger protocol commands without authentication. An attacker can send a crafted eval command over this interface to execute arbitrary PHP code, which may invoke system-level functions such as system() or passthru(). This results in full compromise of the host under the privileges of the web server user.

Affected products

Remediation

Red Hat statement

All Red Hat offerings use fixed versions of the Xdebug package (used for remote debugging) and are therefore not affected. Exploitation would require xdebug to be installed, enabled, and exposed to attackers which is a unlikely configuration in production environments. No Red Hat offerings enable it by default, reducing the severity to Moderate.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 23, 2025
Updated May 15, 2026
Reserved Jul 22, 2025
CISA Vulnrichment
Updated Jul 23, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 23, 2025