Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. pheditor/pheditor
  4. ›
  5. CVE-2026-48030

CVE-2026-48030: Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

June 9, 2026

An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the ‘dir’ POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges.

References

  • github.com/advisories/GHSA-jvc5-6g7q-c843
  • github.com/pheditor/pheditor/commit/62b43df7cb8956a9b0deb9bec278ca8676c890c5
  • github.com/pheditor/pheditor/security/advisories/GHSA-jvc5-6g7q-c843
  • nvd.nist.gov/vuln/detail/CVE-2026-48030

Code Behaviors & Features

Detect and mitigate CVE-2026-48030 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.0.1 before 2.0.4

Fixed versions

  • 2.0.4

Solution

Upgrade to version 2.0.4 or above.

Impact 9.9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

packagist/pheditor/pheditor/CVE-2026-48030.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 12:16:50 +0000.