Vendor
PHP_CodeSniffer versions prior to 3.13.6 and 4.0.2 are vulnerable to command injection via the Gitblame, Hgblame, and Svnblame reports when processing files containing shell metacharacters.