OS Command Injection in Pheditor File Manager by Pheditor
CVE-2026-48030
9.9CRITICAL
What is CVE-2026-48030?
An OS Command Injection vulnerability exists in the Pheditor file manager, affecting versions 2.0.1 to 2.0.3. This vulnerability enables authenticated users to execute arbitrary operating system commands through manipulation of the 'dir' POST parameter. By injecting shell metacharacters, users can bypass security measures meant to restrict command execution, leading to potential remote code execution with web server privileges. The issue is resolved in version 2.0.4.
Affected Version(s)
pheditor >= 2.0.1, < 2.0.4
