THREAT OPS › Threat News › [GHSA] GHSA-hmqg-cxww-wqhq (high) — PHP_CodeSniffer gitblame report command injection via crafted filename
[GHSA] GHSA-hmqg-cxww-wqhq (high) — PHP_CodeSniffer gitblame report command injection via crafted filename
GHSA-hmqg-cxww-wqhq Severity: high CVE: CVE-2026-67434
PHP_CodeSniffer gitblame report command injection via crafted filename
### Impact
PHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the `Gitblame`, `Hgblame` and `Svnblame` report(s).
As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-67434cve
Original source: https://github.com/advisories/GHSA-hmqg-cxww-wqhq