VulnSea

pheditor has 6 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 9.3 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-78 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.3
Publish → KEV
Last 90 days
5 prev 1

Products

  • pheditor/pheditor 6
6
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

pheditor vulnerabilities

CVEs affecting pheditor, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

GHSA-g3hq-hphg-8fhhHigh· 8.8
2mo ago

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Twilightpheditor · pheditor/pheditorvia GHSA
GHSA-f25v-x6vr-962gCritical· 10.0
2mo ago

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Midnightpheditor · pheditor/pheditorvia GHSA
CVE-2026-54540High· 8.8
2mo ago

Pheditor has an authenticated terminal command whitelist bypass

Pheditor has an authenticated terminal command whitelist bypass

Twilightpheditor · pheditor/pheditorEPSS 0.71%via GHSA
CVE-2026-55578High· 8.8
2mo ago

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Twilightpheditor · pheditor/pheditorEPSS 0.36%via GHSA
CVE-2026-55579Critical· 9.8PoC
2mo ago

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise

Abyssalpheditor · pheditor/pheditorEPSS 0.60%via GHSA
CVE-2026-48030Critical· 9.9PoC
3mo ago

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter

Abyssalpheditor · pheditor/pheditorEPSS 5.8%via GHSA
pheditor vulnerabilities (CVEs) · VulnSea