Authenticated terminal command whitelist bypass in Pheditor
Published Jul 27, 2026
8.8
HIGHCVSS 3.1
EPSS 0.73%
Description
Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec(). Shell command substitution such as $() is not blocked, so an authenticated user with the terminal permission can bypass a restricted command allowlist and execute arbitrary shell commands as the web server user. This issue has been patched in version 2.0.5.
Affected products
-
- Version < 2.0.5StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/advisories/GHSA-9643-6xjp-vx57 Advisory
- https://github.com/pheditor/pheditor/releases/tag/2.0.5 x_refsource_MISC
- https://github.com/pheditor/pheditor/security/advisories/GHSA-9643-6xjp-vx57 exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-9643-6xjp-vx57 | Advisory | |
| https://github.com/pheditor/pheditor/releases/tag/2.0.5 | x_refsource_MISC | |
| https://github.com/pheditor/pheditor/security/advisories/GHSA-9643-6xjp-vx57 | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.