Advisories for Composer/Squizlabs/Php_codesniffer package

2022
2017

Arbitrary shell execution

This release contains a fix for a security advisory related to the improper handling of shell commands. Uses of shell_exec() and exec() were not escaping filenames and configuration settings in most cases A properly crafted filename or configuration option would allow for arbitrary code execution when using some features.