AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-65954.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Impact PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()`. The vulnerable method is reached by any sniff that extends `AbstractArrayDeclarationSniff` and calls `getActualArrayKey()`. Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability happens when the method determines the value of an array key using `eval()`. A maliciously crafted array key such as `'system'('id')` would be executed when the code was scanned. ### Known attack vectors Known code paths that reach the vulnerable method include the following PHPCSExtra sniffs: - `Universal.Arrays.DuplicateArrayKey` - `Universal.Arrays.MixedArrayKeyTypes` Other packages that call `AbstractArrayDeclarationSniff::getActualArrayKey()` may also be vulnerable. ### Patches This issue has been fixed in PHPCSUtils 1.2.3. We recommend all users upgrade to 1.2.3 or later. ### Workaround Users who cannot upgrade immediat

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-r6hr-vr92-vv28

Open original source · Updated Sep 29, 2026

PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
composerphpcsstandards/phpcsutils>= 1.0.0-alpha1, < 1.2.31.2.3

Original records & references

PUBLISHED 2026-09-29T13:57:16-04:00
MODIFIED 2026-09-29T13:57:17-04:00
INGESTED 2026-10-06T11:43:08-04:00