HIGH
PHPCSStandards
CVE published 2026-08-06
CVE-2026-67434
The CVE-2026-67434 vulnerability is a command injection issue in PHP_CodeSniffer, a tool used to detect coding standard violations in PHP files. This vulnerability affects PHP_CodeSniffer versions prior to 3.13.6 and 4.0.2. The issue arises when the tool generates reports in Gitblame, Hgblame, or Svnblame formats and processes a file with shell metacharacters in its name, potentially allowing attackers to [truncated]