Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-55579
  • github.com/pheditor/pheditor
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise 27 Jul
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-55578
  • github.com/pheditor/pheditor
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection 27 Jul
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-54540
  • github.com/pheditor/pheditor
Authenticated terminal command whitelist bypass in Pheditor 27 Jul
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-48030
  • github.com/pheditor/pheditor
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78) 27 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-f25v-x6vr-962g
  • Packagist/pheditor/pheditor
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password 24 Jul
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-g3hq-hphg-8fhh
  • Packagist/pheditor/pheditor
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes 24 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-p4h7-p9rj-2pq2
  • Packagist/pheditor/pheditor
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise 16 Jul
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-wg4w-wr5q-6vjc
  • Packagist/pheditor/pheditor
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection 16 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-9643-6xjp-vx57
  • Packagist/pheditor/pheditor
Pheditor has an authenticated terminal command whitelist bypass 16 Jul
  • Fix available
  • Severity - 8.8 (High)
GHSA-jvc5-6g7q-c843
  • Packagist/pheditor/pheditor
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter 09 Jun
  • Fix available
  • Severity - 9.9 (Critical)