


Perceptive Security
SOC/SIEM Consultancy

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the termi…
Published:
27 July 2026 at 00:00:00
Alert date:
27 July 2026 at 23:04:07
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical OS Command Injection vulnerability (CVE-2026-48030) was discovered in Pheditor, a single-file PHP editor and file manager. The flaw exists in versions 2.0.1 through 2.0.3 within the terminal action handler. Authenticated attackers can inject shell metacharacters into the 'dir' POST parameter to execute arbitrary OS commands. The vulnerability completely bypasses the TERMINAL_COMMANDS whitelist security control. Successful exploitation results in full Remote Code Execution (RCE) with web server privileges. The issue has been patched in version 2.0.4. Users are strongly advised to upgrade immediately.
Technical details
Mitigation steps:
Affected products:
Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48030
https://github.com/pheditor/pheditor/releases/tag/2.0.4
https://github.com/pheditor/pheditor/security/advisories/GHSA-jvc5-6g7q-c843
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
