Disclosure summary
### Impact PHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the `Gitblame`, `Hgblame` and `Svnblame` report(s). As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the `Gitblame`, `Hgblame` or `Svnblame` report(s) would process a file whose name contains shell metacharacters. * Users using the default `Full` report, or any of the other non-*blame reports, are not affected. * Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as `"` and `;`, are not affected. ### Patched versions The issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. ### Workaround Users of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the `Gitblame`, `Hgblame` or the `Svnblame` reports when scanning untrusted code. This is especially relevant for CI jobs, pre-commit or review tooling, automated review se
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-hmqg-cxww-wqhq
Open original source · Updated Oct 03, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
Source severity: HIGH / 7.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | squizlabs/php_codesniffer | < 3.13.6 | 3.13.6 |
| composer | squizlabs/php_codesniffer | >= 4.0.0, < 4.0.2 | 4.0.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-08-06T17:31:34-04:00
MODIFIED 2026-10-03T05:47:38-04:00
INGESTED 2026-10-06T11:45:17-04:00