CVE-2026-28409: Php Shell Exec Unsanitized User Input

Unsanitized user-supplied input flows into a shell execution function, enabling OS command injection (CWE-78). Wrap every user-controlled value with escapeshellarg() before concatenating it into a shell string, or replace the shell invocation with proc_open() using an argument array so the shell interpreter is bypassed entirely.

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-28409-php-shell-exec-unsanitized-user-input --engine opengrep

Description

Unsanitized user-supplied input flows into a shell execution function, enabling OS command injection (CWE-78). Wrap every user-controlled value with escapeshellarg() before concatenating it into a shell string, or replace the shell invocation with proc_open() using an argument array so the shell interpreter is bypassed entirely.