Bug 2512312 (CVE-2026-67434)
| Summary: | CVE-2026-67434 squizlabs/php_codesniffer: PHP_CodeSniffer: Arbitrary code execution via crafted filenames in blame reports | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PHP_CodeSniffer. This command injection vulnerability allows an attacker to execute arbitrary shell commands. This occurs when PHP_CodeSniffer processes untrusted files with specially crafted filenames containing shell metacharacters, specifically when generating Gitblame, Hgblame, or Svnblame report formats. This could impact continuous integration pipelines or developer machines reviewing third-party code.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-06 22:28:55 UTC
|