CVE-2026-49260: Escapeshellarg File Check Fallback

Checking an `escapeshellarg` or `escapeshellcmd` escaped string with filesystem functions like `is_executable` or `file_exists` is logically flawed. The escaped string includes shell quote characters, causing the check to fail. If this failed check unexpectedly alters control flow (e.g., falling back to unescaped input), it can result in vulnerabilities like

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-49260-escapeshellarg-file-check-fallback --engine opengrep

Description

Checking an `escapeshellarg` or `escapeshellcmd` escaped string with filesystem functions like `is_executable` or `file_exists` is logically flawed. The escaped string includes shell quote characters, causing the check to fail. If this failed check unexpectedly alters control flow (e.g., falling back to unescaped input), it can result in vulnerabilities like