Critical severity9.9NVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
CVE-2026-48030
CVE-2026-48030
Description
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pheditor/pheditorPackagist | >= 2.0.1, < 2.0.4 | 2.0.4 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.