CVE-2026-65954: PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()
PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey(). The vulnerable method is reached by any sniff that extends AbstractArrayDeclarationSniff and calls getActualArrayKey().
Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host.
The vulnerability happens when the method determines the value of an array key using eval(). A maliciously crafted array key such as 'system'('id') would be executed when the code was scanned.
References
- github.com/FriendsOfPHP/security-advisories/blob/master/phpcsstandards/phpcsutils/CVE-2026-65954.yaml
- github.com/PHPCSStandards/PHPCSUtils/commit/9f596b50ea4498ea57b8cb341e920233b044debf
- github.com/PHPCSStandards/PHPCSUtils/pull/778
- github.com/PHPCSStandards/PHPCSUtils/security/advisories/GHSA-r6hr-vr92-vv28
- github.com/advisories/GHSA-r6hr-vr92-vv28
- nvd.nist.gov/vuln/detail/CVE-2026-65954
Code Behaviors & Features
Detect and mitigate CVE-2026-65954 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →