squizlabs/php_codesniffer
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
Activity
- Latest release
- 1mo ago
- Total releases
- 110
- Cadence
- ~35 days
- Last 12 months
- 6
Reach
- Stars
- 1.5k
Details
- License
- BSD-3-Clause
- First release
- Nov 09, 2012
| Version | Released | |
|---|---|---|
4.0.4
patch
|
4.0.4
patch
Changelog
Compare changes
|
|
4.0.3
patch
|
4.0.3
patch
Changelog
Compare changes
|
|
4.0.2
patch
|
4.0.2
patch
Changelog
Compare changes
|
|
3.13.6
patch
| ||
4.0.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev |
4.0.1
patch
Changelog
Compare changes
|
|
3.13.5
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.13.4
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.13.3
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
4.0.0-RC1
pre
| ||
3.13.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.13.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
4.0.0beta1
pre
| ||
3.13.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.12.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.12.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.12.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.11.3
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev |
3.11.3
patch
Changelog
Compare changes
|
|
3.11.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.11.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.11.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.10.3
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.10.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.10.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.10.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.9.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.9.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.9.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.8.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.8.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.7.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.7.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.7.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.6.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.6.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.6.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.8
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.7
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.6
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.5
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.4
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.3
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.5.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.4.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.4.1
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.4.0
minor
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
2.9.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev | ||
3.3.2
patch
1 CVE
CVE-2026-67434
GHSA-hmqg-cxww-wqhq
Aug 06, 2026
PHP_CodeSniffer gitblame report command injection via crafted filename
High
Local
Low
None
ImpactPHP_CodeSniffer versions before v3.13.6 and v4.0.2 contain a command injection vulnerability in the code creating the As a result, running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Patched versionsThe issue has been fixed in PHP_CodeSniffer v3.13.6 and v4.0.2. We recommend all users upgrade to these versions at their earliest convenience. WorkaroundUsers of PHP_CodeSniffer who cannot upgrade immediately should ensure they do not use the This is especially relevant for CI jobs, pre-commit or review tooling, automated review services, and any service that scans untrusted repositories or uploaded source trees. CreditsMany thanks to both @Faze-up and @edorian for responsibly disclosing this vulnerability. How can I report a security bug?Please report security vulnerabilities privately via the "Security and quality" tab on the PHP_CodeSniffer repository. Affected versions
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.5.0
1.5.0RC1
1.5.0RC2
1.5.0RC3
1.5.0RC4
+ 92 more Show less
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
2.0.0
2.0.0RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0a1
2.0.0a2
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.0.0
3.0.0RC1
3.0.0RC2
3.0.0RC3
3.0.0RC4
3.0.0a1
3.0.1
3.0.2
3.1.0
3.1.1
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.12.0
3.12.1
3.12.2
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.4.0
3.4.1
3.4.2
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.5.5
3.5.6
3.5.7
3.5.8
3.6.0
3.6.1
3.6.2
3.7.0
3.7.1
3.7.2
3.8.0
3.8.1
3.9.0
3.9.1
3.9.2
4.0.0
4.0.1
Fixed in
3.13.6
4.0.2
References
Updated Aug 06, 2026 · Source: OSV.dev |