pheditor/pheditor vulnerabilities
CVEs whose affected-version data names the pheditor/pheditor package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
CVE-2026-54540High· 8.8Pheditor has an authenticated terminal command whitelist bypass
Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-55578High· 8.8Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-55579Critical· 9.8PoCPheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVE-2026-48030Critical· 9.9PoCPheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter