Executive brief
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
Affected products
- Packagist pheditor/pheditor
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-07-24
Technologies: pheditor/pheditor (Packagist). Vendors: Packagist.
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes