Junglewise Threat Intelligence

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: pheditor/pheditor (Packagist). Vendors: Packagist.

Executive brief

Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password

Affected products

  • Packagist pheditor/pheditor

Related threats