THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-786w-p5pm-cvgh (high) — phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers

[GHSA] GHSA-786w-p5pm-cvgh (high) — phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers

highgithub_advisoriesPublished 2026-08-28

GHSA-786w-p5pm-cvgh Severity: high CVE: CVE-2026-55584

phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers

## Summary phpSysInfo's `PSI_ALLOWED` IP allowlist can be trivially bypassed by any unauthenticated remote attacker. The access-control check in `read_config.php` derives the client IP from the attacker-controlled `X-Forwarded-For` and `Client

Indicators of compromise

Original source: https://github.com/advisories/GHSA-786w-p5pm-cvgh