AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-67434.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 03, 2026

Disclosure summary

### Impact PHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the `Gitblame`, `Hgblame` and `Svnblame` report(s). As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the `Gitblame`, `Hgblame` or `Svnblame` report(s) would process a file whose name contains shell metacharacters. * Users using the default `Full` report, or any of the other non-*blame reports, are not affected. * Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as `"` and `;`, are not affected. ### Patched versions The issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. ### Workaround Users of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the `Gitblame`, `Hgblame` or the `Svnblame` reports when scanning untrusted code. This is especially relevant for CI jobs, pre-commit or review tooling, automated review se

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hmqg-cxww-wqhq

Open original source · Updated Oct 03, 2026

PHP_CodeSniffer gitblame report command injection via crafted filename

Source severity: HIGH / 7.3

EcosystemPackageAffected rangeFirst patched
composersquizlabs/php_codesniffer< 3.13.63.13.6
composersquizlabs/php_codesniffer>= 4.0.0, < 4.0.24.0.2

Original records & references

PUBLISHED 2026-08-06T17:31:34-04:00
MODIFIED 2026-10-03T05:47:38-04:00
INGESTED 2026-10-06T11:45:17-04:00