CVE-2026-48030: Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the ‘dir’ POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48030 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →