
New lab: CVE-2026-24895 — FrankenPHP Path Confusion RCE (Unicode) People think "lowercase it" is harmless. In Unicode it’s not. Case folding can do weird mappings (Turkish i, Kelvin sign…), and sometimes worse: UTF-8 byte length changes. FrankenPHP < 1.11.2 did strings.ToLower(path) then used the byte index of ".php" from the lowered string to split the original path. If ToLower() expands bytes → index mismatch → split shifts → SCRIPT_FILENAME can become shell.php.txt → PHP executes the uploaded .txt. Hands-on lab: https://pentesterlab.com/exercises/cve-2026-24895
Post summary
The post introduces the CVE-2026-24895 vulnerability in FrankenPHP, explains the Unicode case‑folding flaw that enables RCE, and provides a lab link for hands‑on exploitation, highlighting the existence of a PoC.


