DescriptionLaravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution via an unserialize pop chain in __destruct in GuzzleHttp\Cookie\FileCookieJar.php.
SourceCVE


check, issue seems to be in src:guzzle, check details

