{"id":"CVE-2026-67434","aliases":["GHSA-hmqg-cxww-wqhq"],"url":"https://o3.security/vulnerability/CVE-2026-67434","summary":"PHP_CodeSniffer gitblame report command injection via crafted filename","details":"PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as \" and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.","published":"2026-08-06T21:31:32.511Z","modified":"2026-09-12T03:30:50.731899692Z","cvss":null,"epss":{"score":0.00701,"percentile":0.51605,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"squizlabs/php_codesniffer","fixedVersion":"3.13.6"},{"ecosystem":"Packagist","name":"squizlabs/php_codesniffer","fixedVersion":"4.0.2"}],"fix":{"url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b","label":"PHPCSStandards/PHP_CodeSniffer@7a3a6bb"},"references":[{"type":"WEB","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6"},{"type":"WEB","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67434.json"},{"type":"ADVISORY","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67434"},{"type":"FIX","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b"},{"type":"FIX","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe"},{"type":"FIX","url":"https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:30:50.731899692Z"}}