pheditor has 6 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 9.3 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-78 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 1
Weakness classes
Products
- pheditor/pheditor 6
Worst active — by depth score
CVE-2026-48030Critical· 9.9Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter68CVE-2026-55579Critical· 9.8Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise66GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password55CVE-2026-54540High· 8.8Pheditor has an authenticated terminal command whitelist bypass49GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes48
pheditor vulnerabilities
CVEs affecting pheditor, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
GHSA-g3hq-hphg-8fhhHigh· 8.8Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
GHSA-f25v-x6vr-962gCritical· 10.0Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password
CVE-2026-54540High· 8.8Pheditor has an authenticated terminal command whitelist bypass
Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-55578High· 8.8Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-55579Critical· 9.8PoCPheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
CVE-2026-48030Critical· 9.9PoCPheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter