VYPR

pheditor

by Pheditor

CVEs (1)

  • CVE-2026-48030criJun 9, 2026
    risk 0.52cvss epss 0.00

    ### Summary An OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving…