OS Command Injection in Pheditor File Manager by Pheditor
CVE-2026-48030

9.9CRITICAL

Key Information:

Vendor

Pheditor

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-48030?

An OS Command Injection vulnerability exists in the Pheditor file manager, affecting versions 2.0.1 to 2.0.3. This vulnerability enables authenticated users to execute arbitrary operating system commands through manipulation of the 'dir' POST parameter. By injecting shell metacharacters, users can bypass security measures meant to restrict command execution, leading to potential remote code execution with web server privileges. The issue is resolved in version 2.0.4.

Affected Version(s)

pheditor >= 2.0.1, < 2.0.4

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.