- Fixed CWD configuration poisoning vulnerability (CVE-2026-25129). Backported Restricted Mode from v0.12. PsySH now requires explicit trust before loading local config (
.psysh.php), local PsySH binaries, or Composer autoloads from untrusted projects. Configure withtrustProjectconfig option,--trust-project/--no-trust-projectCLI flags, orPSYSH_TRUST_PROJECTenv var.