{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/php_codesniffer-3.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-67434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PHP_CodeSniffer (3.x)","PHP_CodeSniffer (4.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PHPCSStandards"],"content_html":"\u003cp\u003ePHP_CodeSniffer contains a critical command injection vulnerability, assigned CVE-2026-67434, affecting its \u003ccode\u003eGitblame\u003c/code\u003e, \u003ccode\u003eHgblame\u003c/code\u003e, and \u003ccode\u003eSvnblame\u003c/code\u003e reporting modules. The issue arises when the tool processes filenames containing shell metacharacters such as backticks, semicolons, or pipes. If these reports are executed against untrusted repositories - common in CI/CD pipelines, automated pull request review services, or local analysis of third-party source code - an attacker can gain arbitrary command execution on the host machine. The vulnerability is present in versions prior to 3.13.6 for the 3.x branch and prior to 4.0.2 for the 4.x branch. Systems running on platforms that permit shell metacharacters in file paths are at highest risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to execute arbitrary system commands with the privileges of the user running the PHP_CodeSniffer process. This poses a significant risk to CI/CD infrastructure, where malicious pull requests or commits can trigger code execution upon analysis, potentially leading to credential exfiltration, persistence, or supply chain compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade PHP_CodeSniffer to version 3.13.6 or 4.0.2 immediately.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, restrict the use of \u003ccode\u003eGitblame\u003c/code\u003e, \u003ccode\u003eHgblame\u003c/code\u003e, or \u003ccode\u003eSvnblame\u003c/code\u003e reports when scanning untrusted source trees.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipeline configurations to identify jobs that utilize these specific reporting flags on untrusted input and switch to the \u003ccode\u003eFull\u003c/code\u003e report or other safe reporting formats.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T03:29:39Z","date_published":"2026-08-07T03:29:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-php-codesniffer-command-injection/","summary":"PHP_CodeSniffer versions prior to 3.13.6 and 4.0.2 are vulnerable to command injection via the Gitblame, Hgblame, and Svnblame reports when processing files containing shell metacharacters.","title":"Command Injection in PHP_CodeSniffer via Malicious Filenames","url":"https://feed.craftedsignal.io/briefs/2026-08-php-codesniffer-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - PHP_CodeSniffer (3.x)","version":"https://jsonfeed.org/version/1.1"}