THREAT OPS › Threat News › [GHSA] GHSA-786w-p5pm-cvgh (high) — phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
[GHSA] GHSA-786w-p5pm-cvgh (high) — phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
GHSA-786w-p5pm-cvgh Severity: high CVE: CVE-2026-55584
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
## Summary phpSysInfo's `PSI_ALLOWED` IP allowlist can be trivially bypassed by any unauthenticated remote attacker. The access-control check in `read_config.php` derives the client IP from the attacker-controlled `X-Forwarded-For` and `Client
Indicators of compromise
- CVE-2026-55584cve
- http://phpsysinfo.sourceforge.net/url
- 8.8.8.8ipv4
Original source: https://github.com/advisories/GHSA-786w-p5pm-cvgh