References https://github.com/emadshanab/goby-poc/blob/main/Symfony-framework-debug-Local-File-Inclusion.json https://medium.com/@p.ra.dee.p_0xx01/bug-multiple-vulnerabilities-in-symfony-profiler-debug-mode-a81c385c9728 https://blog.csdn.net/kk1234/article/details/155045013 https://infosecwriteups.com/how-i-was-able-to-find-multiple-vulnerabilities-of-a-symfony-web-framework-web-application-2b82cd5de144 https://www.vaadata.com/en/blog/symfony-security-best-practices-vulnerabilities-and-attacks/ https://www.leavesongs.com/PENETRATION/edusoho-debug-user-information-disclose.html https://pentest-tools.com/vulnerabilities-exploits/symfony-profiler-remote-access-via-injected-arguments_23822 https://www.acunetix.com/vulnerabilities/web/symfony-debug-mode-enabled/ https://blog.lexfo.fr/symfony-secret-fragment.html https://blog.nollium.com/cve-2024-50340-remote-access-to-symfony-profiler-via-injected-arguments-d2f14b4f6ad7 https://www.invicti.com/web-application-vulnerabilities/symfony-web-debug-toolbar
Related VulnerabilitiesPoCCVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug DisclosurePoCaspx-debug-mode: ASP.NET Debugging EnabledPoCfastly-debug-headers: Fastly CDN Debug Headers ExposureJava Debug Wire Protocol 代码执行漏洞Dgraph /debug/vars 信息泄露漏洞(CVE-2026-41492)PoCCVE-2026-39352: Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalPoCfrappe-default-login: Frappe Framework - Default Login CredentialsPoClaravel-debugbar-exposure: Laravel Debugbar - Sensitive Information ExposureSymfony /_profiler/phpinfo 信息泄露漏洞(CVE-2024-50340)PoCCVE-2025-41242: Spring Framework - Path TraversalPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksPoCCVE-2025-64500: Symfony HttpFoundation - Access Control Bypass via PATH_INFOPoCblockchain-rpc-debug-exposure: Blockchain RPC Debug Trace Methods - Exposure