---
id: CVE-2026-103475
title: >-
  yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP
  addresses by setting allowedIPs to ['*'] in its default development
  configuration
summary: >-
  yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP
  addresses by setting allowedIPs to ['*'] in its default development
  configuration. Unauthenticated remote attackers can access the debug endpoint
  to read sens…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-489
vendor: yii2-starter-kit
product: yii2-starter-kit
affected:
  - yii2-starter-kit <= 4.2.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:31.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103475'
references:
  - url: 'https://github.com/yii-starter-kit/yii2-starter-kit'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21
    label: disclosure@vulncheck.com
  - url: 'https://github.com/yii-starter-kit/yii2-starter-kit/issues/797'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-30T19:13:17.145317Z'
ingestedAt: '2026-09-30T18:17:24.547Z'
---

## Overview

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
