CVE-2026-67434High· 7.8▾ TwilightPHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgbl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.7%
Last analysed / modified upstream
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
squizlabs/php_codesniffer < 3.13.6squizlabs/php_codesniffer >= 4.0.0, < 4.0.2Patched in:
squizlabs/php_codesniffer 3.13.6squizlabs/php_codesniffer 4.0.2Source: https://github.com/advisories/GHSA-hmqg-cxww-wqhq
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85013High· 7.3A flaw was found in environment-modules
CVE-2026-10805Medium· 6.7A flaw was found in NetworkManager
CVE-2025-69262High· 7.5pnpm is a package manager
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices