Skip to content
Threat Feed
high advisory

PHPCSUtils Arbitrary Code Execution via AbstractArrayDeclarationSniff

PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 are vulnerable to remote code execution due to insecure use of eval() within the AbstractArrayDeclarationSniff::getActualArrayKey() method.

PHPCSUtils, a utility library used by PHP_CodeSniffer for static analysis, contains a critical arbitrary code execution vulnerability identified as CVE-2026-65954. The issue resides in the PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey() method, which performs improper input validation when processing array keys. Specifically, the method utilizes the eval() function to determine key values, allowing an attacker to inject arbitrary PHP code within a maliciously crafted array key.

This vulnerability impacts any linting or static analysis pipeline that utilizes PHP_CodeSniffer with rulesets extending the vulnerable AbstractArrayDeclarationSniff class. Notable examples of affected downstream sniffs include Universal.Arrays.DuplicateArrayKey and Universal.Arrays.MixedArrayKeyTypes from the PHPCSExtra package. Defenders should note that this vulnerability can be triggered automatically during CI/CD processes, pull request linting, or local developer analysis if the scanned target repository contains malicious PHP code. Successful exploitation results in the execution of arbitrary commands with the privileges of the user running the PHPCS process.

Attack Chain

  1. Attacker crafts a malicious PHP file containing an array with a specially formatted key, such as 'system'('id').
  2. The target environment initiates a static analysis scan using phpcs.
  3. The scanning engine loads a ruleset that includes a sniff extending AbstractArrayDeclarationSniff.
  4. The scanner identifies the malicious array structure and triggers the getActualArrayKey() method.
  5. The method passes the malicious array key string directly into an eval() call.
  6. The PHP runtime executes the injected code within the context of the scanning host's user.
  7. The attacker achieves arbitrary code execution on the build server, developer workstation, or CI/CD container.

Impact

Successful exploitation allows for full command execution on the host machine running the static analysis. This poses a significant risk to CI/CD environments where pull requests from untrusted contributors are automatically scanned. If the scanning host is compromised, attackers may gain access to sensitive repository secrets, pipeline environment variables, or establish persistence within the development infrastructure.

Recommendation

  1. Upgrade PHPCSUtils to version 1.2.3 or later immediately to resolve CVE-2026-65954.
  2. If an immediate upgrade is not feasible, identify and disable the affected sniffs (e.g., Universal.Arrays.DuplicateArrayKey and Universal.Arrays.MixedArrayKeyTypes) within your ruleset XML files using the <exclude> tag.
  3. Verify the removal of affected sniffs by executing phpcs -e --standard=/path/to/ruleset.xml to ensure they no longer appear in the active sniff list.
  4. Monitor CI/CD logs for processes spawning shells or making unexpected network connections initiated by the PHPCS linter.

Immediate actions

Upgrade PHPCSUtils to version 1.2.3 or later

DevOps 24h

Mitigations

Disable vulnerable sniffs via XML ruleset configuration

immediate DevOps

CVE-2026-65954