


Perceptive Security
SOC/SIEM Consultancy

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the termi…
Published:
26 July 2026 at 22:00:00
Alert date:
27 July 2026 at 19:02:54
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A critical OS Command Injection vulnerability (CVE-2026-48030) was discovered in Pheditor, a single-file PHP editor and file manager. The flaw affects versions 2.0.1 through 2.0.3 and resides in the terminal action handler. Authenticated users can exploit the vulnerability by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist. Successful exploitation allows full Remote Code Execution (RCE) with web server privileges. The vulnerability requires authentication but poses a severe risk once an attacker has valid credentials. The issue has been patched in version 2.0.4. Users are strongly advised to upgrade immediately to mitigate the risk of full system compromise.
Technical details
Mitigation steps:
Affected products:
Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48030
https://github.com/pheditor/pheditor/releases/tag/2.0.4
https://github.com/pheditor/pheditor/security/advisories/GHSA-jvc5-6g7q-c843
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
