CVE-2026-65954 with a CVSS score of 8.6 is a vulnerability affecting phpcsstandards/phpcsutils versions >= 1.0.0-alpha1, < 1.2.3 in PHPCSUtils versions 1.0.0-alpha1 through 1.2.2, allowing arbitrary code execution via eval in AbstractArrayDeclarationSniff::getActualArrayKey. The vulnerable method is reached by any sniff that extends AbstractArrayDeclarationSniff and calls getActualArrayKey, leading to command execution on the scanning host when PHPCS runs over untrusted PHP code through such a sniff. This happens when the method determines the value of an array key using eval, executing maliciously crafted array keys like 'system'('id'). Known attack vectors include the Universal.Arrays.DuplicateArrayKey and Universal.Arrays.MixedArrayKeyTypes sniffs, as well as other packages calling AbstractArrayDeclarationSniff::getActualArrayKey. The business impact is significant, allowing attackers to execute arbitrary commands on the scanning host.
We recommend you to update PHPCSUtils to version 1.2.3 or 1.2.3.[/subscribe_to_unlock_form]
CVE-2026-65954 with a CVSS score of 8.6 is a vulnerability affecting phpcsstandards/phpcsutils versions >= 1.0.0-alpha1, < 1.2.3 in PHPCSUtils versions 1.0.0-alpha1 through 1.2.2, allowing arbitrary code execution via eval in AbstractArrayDeclarationSniff::getActualArrayKey. The vulnerable method is reached by any sniff that extends AbstractArrayDeclarationSniff and calls getActualArrayKey, leading to command execution on the scanning host when PHPCS runs over untrusted PHP code through such a sniff. This happens when the method determines the value of an array key using eval, executing maliciously crafted array keys like 'system'('id'). Known attack vectors include the Universal.Arrays.DuplicateArrayKey and Universal.Arrays.MixedArrayKeyTypes sniffs, as well as other packages calling AbstractArrayDeclarationSniff::getActualArrayKey. The business impact is significant, allowing attackers to execute arbitrary commands on the scanning host.
We recommend you to update PHPCSUtils to version 1.2.3 or 1.2.3.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]