PHPCSUtils, Arbitrary Code Execution via eval(), CVE-2026-65954 (Critical) -DC-Sep2026-2611

Listen to this Post

PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in the `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()` method. The vulnerable method is reachable by any sniff that extends `AbstractArrayDeclarationSniff` and calls getActualArrayKey(). Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability occurs when the method determines the value of an array key using eval(). The source code of the key expression from the file under analysis is passed directly to `eval()` as shown in the vulnerable code path: $key = eval('return ' . $content . ';' . \PHP_EOL);. Here `$content` is text from the file being analysed. A maliciously crafted array key such as `’system'(‘id’)` would therefore not be evaluated, but executed when the code was scanned. Known code paths that reach the vulnerable method include the PHPCSExtra sniffs `Universal.Arrays.DuplicateArrayKey` and Universal.Arrays.MixedArrayKeyTypes. Other packages that call `AbstractArrayDeclarationSniff::getActualArrayKey()` may also be vulnerable. This issue has been fixed in PHPCSUtils 1.2.3. The vulnerability was assigned CVE-2026-65954 and GHSA-r6hr-vr92-vv28, rated high with a CVSS score of 8.6.

DailyCVE Form:

Platform: PHPCSUtils
Version: 1.0.0-alpha1-1.2.2
Vulnerability: Arbitrary Code Execution
Severity: Critical (CVSS 8.6)
date: 2026-07-27

Prediction: Patch released 2026-07-27

What Undercode Say

Analytics

Check installed PHPCSUtils version
composer show phpcsstandards/phpcsutils
Run PHPCS with sniffs to verify vulnerability
phpcs --standard=Universal /path/to/code
List all sniffs in a standard with -e flag
phpcs -e --standard=/path/to/ruleset.xml
// Vulnerable code path in AbstractArrayDeclarationSniff.php
$key = eval('return ' . $content . ';' . \PHP_EOL);

How Exploit: (Educational Purposes!)

// Malicious array key crafted for execution during PHPCS scan
$array = [
'system'('id') => 'value'
];
// Alternative payload using assert
$array = [
assert('system("id")') => 'value'
];
CI pipeline scenario - linting a malicious PR
phpcs --standard=Universal malicious-code.php
Output: uid=33(www-data) gid=33(www-data) groups=33(www-data)

Protection: from this CVE

Upgrade to PHPCSUtils 1.2.3 or later
composer require phpcsstandards/phpcsutils:^1.2.3
<!-- Workaround: disable vulnerable sniffs in custom ruleset -->
<rule ref="Universal">
<exclude name="Universal.Arrays.DuplicateArrayKey"/>
<exclude name="Universal.Arrays.MixedArrayKeyTypes"/>
</rule>
Verify sniffs are disabled
phpcs -e --standard=/path/to/ruleset.xml

Impact

Arbitrary command execution on the scanning host when PHPCS processes untrusted PHP code through vulnerable sniffs. Affects CI pipelines that lint pull requests and developer machines reviewing third-party code.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top