THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hmqg-cxww-wqhq (high) — PHP_CodeSniffer gitblame report command injection via crafted filename

[GHSA] GHSA-hmqg-cxww-wqhq (high) — PHP_CodeSniffer gitblame report command injection via crafted filename

medgithub_advisoriesPublished 2026-08-06

GHSA-hmqg-cxww-wqhq Severity: high CVE: CVE-2026-67434

PHP_CodeSniffer gitblame report command injection via crafted filename

### Impact

PHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the `Gitblame`, `Hgblame` and `Svnblame` report(s).

As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hmqg-cxww-wqhq