PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()
PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey(). The vulnerable method is reached by any sniff that extends AbstractArrayDeclarationSniff and calls getActualArrayKey(). Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability happens when the …