Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.9epss 1.5%
from disclosure to weapon0 days
Published on NVDJul 27
1st PoCMay 28
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
pheditor · pheditorpublic PoCs found — 1
githubgithub.com/muslimbek-0x/CVE-2026-48030★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.