Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

0
High
Published: 07/24/2026 (07/24/2026, 21:45:40 UTC)
Source: GCVE Database
Product: pheditor/pheditor

Description

Pheditor's terminal feature enforces an allowlist of commands by prefix matching but does not validate command arguments. This allows attackers with terminal permission to execute arbitrary commands by abusing allowlisted binaries that accept options enabling code execution. The vulnerability bypasses prior metacharacter sanitization fixes and leads to remote code execution under the web server's privileges. The default configuration includes a hardcoded admin password, amplifying the risk by enabling unauthenticated RCE. The issue affects versions prior to 2.0.7.

CVSS v3.1

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Packagistghsa
pheditor/pheditor
Affected versions
<2.0.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:52:56 UTC

Technical Analysis

Pheditor's terminal feature restricts commands to an allowlist using a prefix match without validating arguments. The allowlist includes binaries such as find, git, php, tar, and grep, which can execute arbitrary commands via their options. The code rejects shell metacharacters but does not reject spaces or flags that enable command execution. Commands are executed through shell_exec without argument sanitization, allowing attackers to bypass restrictions by crafting commands that start with an allowlisted binary and include malicious arguments. This vulnerability is distinct from prior metacharacter injection issues and results in arbitrary command execution for users with terminal permission. The default deployment's hardcoded admin password further increases exposure.

Potential Impact

Allows arbitrary command execution on the host with the web server's privileges by users with terminal permission. Due to a hardcoded default admin password with no forced change, attackers can gain authenticated access easily, effectively enabling unauthenticated remote code execution. This can lead to full system compromise depending on the web server's privileges.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Recommended mitigations include validating the full command and its arguments rather than just the prefix, rejecting dangerous flags for allowlisted binaries, running commands as argv arrays through a restricted launcher without a shell, or removing binaries capable of code execution from the allowlist. Until an official fix is available, avoid enabling the terminal feature or restrict terminal permissions to trusted users only.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-g3hq-hphg-8fhh
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["Packagist"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a6542259c2644c7f8089cf4

Added to database: 07/25/2026, 23:09:25 UTC

Last enriched: 07/25/2026, 23:52:56 UTC

Last updated: 07/26/2026, 03:54:40 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses