Vulnerability record · CVE-2020-13756 · published 3 June 2020
CVE-2020-13756: Sabberworm PHP CSS Parser eval injection allows remote code execution
SSabberworm · Php Css Parser
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, so attacker-supplied CSS can be executed as PHP code. The flaw is reachable when the allSelectors() or getSelectorsBySpecificity() functions are called with attacker-controlled input, making it a serious risk for any application that parses untrusted CSS.
Description
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and public exploit references make this a critical remote code execution risk.
What it is
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, so attacker-supplied CSS can be executed as PHP code. The flaw is reachable when the allSelectors() or getSelectorsBySpecificity() functions are called with attacker-controlled input, making it a serious risk for any application that parses untrusted CSS.
Impact
An attacker can execute arbitrary PHP code in the context of the web application, leading to full compromise of confidentiality, integrity and availability of the affected host.
Attack surface
The vulnerability is network-reachable with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). It is triggered when the application passes attacker-controlled CSS into allSelectors() or getSelectorsBySpecificity().
Exploitation
Public exploit references exist (Packet Storm and Full Disclosure entries tagged Exploit), and EPSS estimates a 30-day exploitation probability of about 0.498 (98.8th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.
What to do
- Upgrade Sabberworm PHP CSS Parser to version 8.3.1 or later, which contains the patch commit 2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4.
- If immediate upgrade is not possible, avoid calling allSelectors() or getSelectorsBySpecificity() on untrusted CSS input.
- Sanitize or strictly validate any CSS passed into the parser, and treat all external CSS as untrusted.
- Check for bundled or vendored copies of the library in dependencies and update those as well.
Detection
- Search application and dependency manifests for Sabberworm PHP CSS Parser versions below 8.3.1.
- Monitor PHP error and application logs for eval-related errors or unexpected code execution originating from CSS parsing paths.
- Review code paths that call allSelectors() or getSelectorsBySpecificity() to confirm whether input can be attacker-controlled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157923/Sabberworm-PHP-CSS-Code-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2020/Jun/7 | ExploitMailing ListThird Party Advisory |
| https://github.com/sabberworm/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4 | PatchThird Party Advisory |
| https://github.com/sabberworm/PHP-CSS-Parser/releases/tag/8.3.1 | Release NotesThird Party Advisory |
| http://packetstormsecurity.com/files/157923/Sabberworm-PHP-CSS-Code-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2020/Jun/7 | ExploitMailing ListThird Party Advisory |
| https://github.com/sabberworm/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4 | PatchThird Party Advisory |
| https://github.com/sabberworm/PHP-CSS-Parser/releases/tag/8.3.1 | Release NotesThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00013.html |
Track CVE-2020-13756 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13756), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.