Executive brief
Pheditor is a web-based file manager and code editor. A security flaw in its terminal feature allows an authorized user to bypass command restrictions and run unauthorized commands on the underlying server. This could lead to a complete takeover of the web server, unauthorized access to sensitive files, or disruption of services.
Technical details
Pheditor's terminal feature implements a command allowlist by checking if a user-provided string starts with a permitted command (e.g., 'ls'). However, the application fails to sanitize shell metacharacters used for command substitution, such as '$()'. Because the entire unsanitized string is subsequently passed to the PHP 'shell_exec()' function, an authenticated attacker with terminal permissions can append malicious commands (e.g., 'ls$(whoami)') to a permitted prefix. This results in arbitrary command execution with the privileges of the web server user. The issue is fixed in version 2.0.5 by improving validation of shell metacharacters.
Affected products
- pheditor Pheditor < 2.0.5
Timeline
- 2026-06-05: patched: Version 2.0.5 released to address the vulnerability.
- 2026-07-27: advisory: CVE-2026-54540 published.