CVE-2026-48030
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4.
| CWE | CWE-78 |
| Vendor | pheditor |
| Product | pheditor |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for pheditor pheditor
Be the first to know when new critical vulnerabilities affecting pheditor pheditor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
pheditor / pheditor
>= 2.0.1, < 2.0.4