QCubed versions before 3.2 are covered by a critical advisory for PHP object injection in the profiler endpoint [S1][S2][S3][S5].
Root Cause
The advisory describes profile.php processing untrusted profiler data with PHP deserialization in affected releases [S4][S5]. PHP object injection risk depends on the deployed code path and available gadget classes, so dependency evidence should be treated as patch-priority advisory context rather than automatic proof of code execution.
Impact
If a vulnerable QCubed deployment exposes the profiler endpoint and accepts untrusted serialized data, attackers may be able to trigger application object lifecycle behavior and, in some deployments, reach remote code execution [S1][S2][S5]. The practical impact depends on deployment exposure, access controls, installed classes, and whether a downstream build backported the fix without changing package version.
Affected Versions
GitHub Advisory and OSV list the Packagist package qcubed/qcubed as affected through 3.1.1 and fixed in 3.2 [S2][S3]. NVD also tracks CVE-2020-24914 for QCubed versions up to and including 3.1.1 [S1].
Fixes and Mitigations
Upgrade qcubed/qcubed to 3.2 or newer, regenerate composer.lock, rebuild deployment artifacts, and verify the deployed PHP host or container no longer contains the affected framework version [S2][S3][S4]. Disable, remove, authenticate, or restrict QCubed profiling functionality while rollout completes.
How FixVibe covers it
FixVibe's GitHub repo scans flag Composer evidence that qcubed/qcubed resolves below 3.2, so you can upgrade.
