Junglewise Threat Intelligence

Pheditor RCE via terminal command allowlist bypass

Severity: high · CVSS 8.8 · Published 2026-07-24

Technologies: Pheditor, pheditor/pheditor (Packagist). Vendors: Pheditor, Packagist.

Executive brief

Pheditor, a web-based code editor, contains a vulnerability in its terminal feature that allows users to bypass security restrictions. While the tool attempts to limit users to a specific list of safe commands, it fails to properly check the arguments provided to those commands. An attacker with basic access can use this flaw to execute arbitrary code on the server, potentially leading to a full system takeover and theft of sensitive data.

Technical details

Pheditor's terminal feature implements a command allowlist (TERMINAL_COMMANDS) using a prefix-based string match and a denylist for shell metacharacters. However, it fails to validate the arguments following the allowlisted command. Because the allowlist includes powerful binaries like 'find', 'git', 'php', and 'tar', an attacker can use legitimate flags (such as 'find -exec' or 'php -r') to execute arbitrary OS commands. The vulnerability exists in pheditor.php because it uses shell_exec() on the unvalidated command string. This bypass persists even after previous fixes for metacharacter injection. A patch is available in version 2.0.7.

Affected products

  • pheditor Pheditor <= 2.0.6

Timeline

  • 2026-07-23: disclosed
  • 2026-07-24: advisory: GHSA-g3hq-hphg-8fhh published
  • 2026-07-24: patched: Version 2.0.7 released

References

Related threats