CVE-2026-48030 is an OS command injection vulnerability in Pheditor, a PHP-based single-file editor and file manager. Affected versions are 2.0.1 through 2.0.3, corresponding to versions greater than or equal to 2.0.1 and less than 2.0.4. The flaw is present in the terminal action handler, where the dir POST parameter is passed to shell execution without proper sanitization. By injecting shell metacharacters into this parameter, an authenticated user can bypass the application's terminal command whitelist and cause arbitrary operating system commands to be executed. Successful exploitation results in remote code execution in the security context of the web server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC for CVE-2026-48030 affecting Pheditor <= 2.0.3. It contains two files: a README documenting the vulnerability, affected versions, vulnerable code path, and usage example; and `poc.py`, the actual exploit script. The exploit is not part of a larger framework. The Python script uses `requests` to authenticate to a target `pheditor.php` endpoint with a supplied password, retrieve a CSRF token from the returned HTML using a regex (`token = "([a-f0-9]+)"`), and then exploit the terminal action by POSTing `action=terminal`, a valid `token`, `command=ls`, and a malicious `dir` value. The injected `dir` is constructed as `/tmp; {command} #`, which escapes the intended `cd <dir> && ls` flow and causes arbitrary shell command execution on the server. Capabilities are broader than simple detection: the script first verifies exploitation by running `id` and checking for `uid=` in the response, then supports three operator modes: one-shot command execution via `--cmd`, an interactive pseudo-shell via repeated token retrieval and command submission with `--shell`, and webshell deployment via `--webshell`, which writes `<?php system($_GET['c']);?>` to `<webroot>/shell.php` and tests it over HTTP. Because it includes working post-exploitation actions and a hardcoded webshell payload, this is best classified as OPERATIONAL rather than a basic PoC. Fingerprintable targets and artifacts are limited and mostly operator-supplied: the main network target is the provided Pheditor URL such as `http://TARGET/pheditor.php`; the exploit references local/remote filesystem paths `/tmp`, `/var/www/html`, and `/shell.php`; and the dropped webshell is accessed with query parameter `c`. Overall, the repository’s purpose is to demonstrate and operationalize authenticated remote OS command injection in vulnerable Pheditor installations.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An OS command injection vulnerability in Pheditor 2.0.1 through 2.0.3 caused by passing the dir parameter to shell_exec() without sanitization in the terminal action handler.
An OS command injection vulnerability in Pheditor's terminal action handler that allows an authenticated user to achieve arbitrary command execution and full remote code execution with web server privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.