pheditor's terminal feature restricts callers to an allowlist of commands (TERMINAL_COMMANDS) and rejects shell metacharacters. The allowlist is enforced as a PREFIX match with no argument validation, and the allowlist includes binaries that grant arbitrary command execution through their own options (find, git, php, tar, grep). A caller can therefore run any command using only allowlisted binaries and no rejected metacharacter, escaping the allowlist restriction the terminal feature relies on.
The prior terminal advisories were all shell-metacharacter injections: GHSA-9643-6xjp-vx57 ($()), GHSA-wg4w-wr5q-6vjc (|, backtick, newline), GHSA-jvc5-58fv-w8cq (; via the dir field). The current code rejects those characters. This report is a different class — CWE-88 argument injection through an allowlisted binary's flags — which the metacharacter denylist does not address.
In the terminal action handler of pheditor.php:
:588 rejects &, ;, |, $, backtick, \n, \r. It does NOT reject space, -, {, }, +, /, ..:595-605 checks the command against TERMINAL_COMMANDS (defined :25: ls,...,php,...,git,find,grep,...,tar,...,composer,exit) using a PREFIX match: strlen($command) >= strlen($value) && substr($command, 0, strlen($value)) == $value. There is no word boundary and no validation of the arguments that follow.:617 runs the command through the shell unchanged: shell_exec((empty($dir) ? null : 'cd ' . escapeshellarg($dir) . ' && ') . $command . ' && echo \ ; pwd').So a command beginning with an allowlisted binary, carrying a code-exec flag, and containing none of the rejected characters reaches shell_exec intact.
POST to the terminal action with:
command = find . -maxdepth 0 -exec touch /tmp/PWNED {} +
dir = (any)
This contains...
2.0.7Exploitability
AV:NAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:H8.8/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H