CVE-2020-13756

CRITICAL EXPLOITED IN THE WILD

sabberworm/php_css_parser < 8.3.1 - Remote Code Execution via eval in allSelectors or getSelectorsBySpecificity

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-13756 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including KrE80r.

AI-analyzed exploit summary This repository provides a vulnerable Docker environment for CVE-2020-13756, a remote code execution vulnerability in Sabberworm PHP CSS Parser. The exploit demonstrates how unsanitized user input passed to `getSelectorsBySpecificity()` leads to arbitrary code execution via `eval()`.

Description

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

Exploits (1)

nomisec WORKING POC
by KrE80r · poc
https://github.com/KrE80r/CVE-2020-13756-env

This repository provides a vulnerable Docker environment for CVE-2020-13756, a remote code execution vulnerability in Sabberworm PHP CSS Parser. The exploit demonstrates how unsanitized user input passed to `getSelectorsBySpecificity()` leads to arbitrary code execution via `eval()`.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Sabberworm PHP CSS Parser < 8.3.1
No auth needed
Prerequisites: Docker · Sabberworm PHP CSS Parser < 8.3.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/sabberworm/PHP-CSS-Parser/releases/tag/8.3.1
Exploit, Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2020/Jun/7
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/157923/Sabberworm-PHP-CSS-Code-Injection.html

Scores

CVSS v3 9.8
EPSS 0.2785
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-01-12
InTheWild.io 2022-01-12
CWE
CWE-94
Status published
Products (2)
sabberworm/php-css-parser 8.3.0 - 8.3.1Packagist
sabberworm/php_css_parser < 8.3.1
Published Jun 03, 2020
Tracked Since Feb 18, 2026