top of page
perceptive_background_267k.jpg

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplet…

Published:

26 juli 2026 om 22:00:00

Alert date:

27 juli 2026 om 21:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

Pheditor, a single-file PHP editor and file manager, contains a critical command injection vulnerability in versions 2.0.1 through 2.0.5. The terminal feature uses an incomplete character blocklist when sanitizing user input before passing it to shell_exec(). Despite a prior fix that added the dollar sign ($) to the blocklist, the pipe (|), backtick (`), and newline byte (0x0A) characters remain unblocked. An authenticated user with terminal permissions (enabled by default) can exploit these characters to bypass the TERMINAL_COMMANDS allowlist and execute arbitrary OS commands as the web server user. This represents a bypass of a previous security fix (GHSA-9643-6xjp-vx57). The vulnerability has been fully patched in version 2.0.6 of Pheditor.

Technical details

Mitigation steps:

Affected products:

Pheditor 2.0.1
Pheditor 2.0.2
Pheditor 2.0.3
Pheditor 2.0.4
Pheditor 2.0.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page