Disclosure summary
### Impact PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()`. The vulnerable method is reached by any sniff that extends `AbstractArrayDeclarationSniff` and calls `getActualArrayKey()`. Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability happens when the method determines the value of an array key using `eval()`. A maliciously crafted array key such as `'system'('id')` would be executed when the code was scanned. ### Known attack vectors Known code paths that reach the vulnerable method include the following PHPCSExtra sniffs: - `Universal.Arrays.DuplicateArrayKey` - `Universal.Arrays.MixedArrayKeyTypes` Other packages that call `AbstractArrayDeclarationSniff::getActualArrayKey()` may also be vulnerable. ### Patches This issue has been fixed in PHPCSUtils 1.2.3. We recommend all users upgrade to 1.2.3 or later. ### Workaround Users who cannot upgrade immediat
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-r6hr-vr92-vv28
Open original source · Updated Sep 29, 2026
PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| composer | phpcsstandards/phpcsutils | >= 1.0.0-alpha1, < 1.2.3 | 1.2.3 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T13:57:16-04:00
MODIFIED 2026-09-29T13:57:17-04:00
INGESTED 2026-10-06T11:43:08-04:00