Stopgap hardening package for the Sansec‑disclosed StyleSmuggler RCE: Nginx/Apache request filters, a DI‑scanner CLI guard, a sanitizing module, and scripts for compromise checks, containment, and DB audits. Includes deployment, testing, and incident‑response runbooks; designed to be removed once an official fix ships.
Patch enforcing CLI-only execution for DI scanners to mitigate StyleSmuggler, adding PHP_SAPI checks in ArrayScanner, ClassesScanner, and XmlInterceptorScanner.