CVE-2026-28409: Php Shell Exec Unsanitized User Input
Unsanitized user-supplied input flows into a shell execution function, enabling OS command injection (CWE-78). Wrap every user-controlled value with escapeshellarg() before concatenating it into a shell string, or replace the shell invocation with proc_open() using an argument array so the shell interpreter is bypassed entirely.
greprules fetch cve-2026-28409-php-shell-exec-unsanitized-user-input --engine opengrepDescription
Unsanitized user-supplied input flows into a shell execution function, enabling OS command injection (CWE-78). Wrap every user-controlled value with escapeshellarg() before concatenating it into a shell string, or replace the shell invocation with proc_open() using an argument array so the shell interpreter is bypassed entirely.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.