PatchSiren

PHPCSStandards CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PHPCSStandards CVE published 2026-08-06

CVE-2026-67434

The CVE-2026-67434 vulnerability is a command injection issue in PHP_CodeSniffer, a tool used to detect coding standard violations in PHP files. This vulnerability affects PHP_CodeSniffer versions prior to 3.13.6 and 4.0.2. The issue arises when the tool generates reports in Gitblame, Hgblame, or Svnblame formats and processes a file with shell metacharacters in its name, potentially allowing attackers to [truncated]