PatchSiren

PHPCSStandards CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PHPCSStandards CVE published 2026-08-06

CVE-2026-67434

PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. This issue allows attacker-controlled shell commands to be executed when processing files with shell metacharacters in their names, potentially impacting continuous integration pipelines and developer machines reviewing third-party code. The vulnerability is fixed in ve [truncated]