Impact
CVE-2019-19576 is a critical unrestricted-upload advisory for verot/class.upload.php. The reviewed advisory covers releases before 1.0.3 and releases from 2.0.0 through 2.0.3 [S1][S2]. In an application that exposes the affected upload handling to untrusted users and stores resulting files where PHP can execute them, the flaw can contribute to remote code execution. Dependency presence alone does not establish those runtime conditions.
Root Cause
Affected releases did not include .phar in the library's dangerous-extension handling. The upstream fixes add that extension to the relevant checks on both maintained release lines [S3][S4]. Version 1.0.3 fixes the 1.x line, and version 2.0.4 fixes the 2.x line [S1][S2].
How FixVibe covers it
FixVibe's GitHub repo scans flag verot/class.upload.php versions affected by CVE-2019-19576 in composer.lock and composer.json, reported as high-severity advisories with the file and version.
Remediation
Upgrade to version 1.0.3 or newer on the 1.x release line, or version 2.0.4 or newer on the 2.x release line [S1][S2]. Regenerate composer.lock, rebuild every PHP host or container that installs the dependency, confirm the deployed version, and rerun the FixVibe repo scan.
As defense in depth, keep uploaded files outside the web root or disable script execution in upload storage, generate filenames server-side, and validate content against a narrow allowlist. Verify the change through dependency inspection, configuration review, and benign upload regression tests rather than dangerous proof files.
