Threat Advisory

PHP CodeSniffer Vulnerability Impacts Untrusted Source Scanning Workflows

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-67434 with a CVSS score of 7.3 is a command injection vulnerability affecting the PHP_CodeSniffer package. The flaw exists within the code responsible for generating Gitblame, Hgblame, and Svnblame report formats, where the application fails to properly sanitize input. An attacker can exploit this issue by enticing a target to scan a malicious file containing shell metacharacters in its filename, specifically when the tool is configured to generate one of the affected blame reports. Successful exploitation allows the attacker to execute arbitrary shell commands on the underlying system with the privileges of the scanning process. This poses a significant risk to continuous integration pipelines, automated code review services, and developer environments, potentially leading to system compromise or further unauthorized access within the network. Exploitation requires that the victim processes untrusted files using the specific blame report types on a platform permitting such filenames, while users utilizing the default Full report are not impacted.

RECOMMENDATION:

We recommend you to update PHP_CodeSniffer to version 3.13.6 or 4.0.4 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-67434 with a CVSS score of 7.3 is a command injection vulnerability affecting the PHP_CodeSniffer package. The flaw exists within the code responsible for generating Gitblame, Hgblame, and Svnblame report formats, where the application fails to properly sanitize input. An attacker can exploit this issue by enticing a target to scan a malicious file containing shell metacharacters in its filename, specifically when the tool is configured to generate one of the affected blame reports. Successful exploitation allows the attacker to execute arbitrary shell commands on the underlying system with the privileges of the scanning process. This poses a significant risk to continuous integration pipelines, automated code review services, and developer environments, potentially leading to system compromise or further unauthorized access within the network. Exploitation requires that the victim processes untrusted files using the specific blame report types on a platform permitting such filenames, while users utilizing the default Full report are not impacted.

RECOMMENDATION:

We recommend you to update PHP_CodeSniffer to version 3.13.6 or 4.0.4 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu