Junglewise Threat Intelligence

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE , surviving vector after the metacharacter-sanitization fixe

Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: pheditor/pheditor (Packagist). Vendors: Packagist.

Executive brief

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Affected products

  • Packagist pheditor/pheditor

Related threats