PHPCSUtils Arbitrary Code Execution via AbstractArrayDeclarationSniff
PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 are vulnerable to remote code execution due to insecure use of eval() within the AbstractArrayDeclarationSniff::getActualArrayKey() method.
PHPCSUtils, a utility library used by PHP_CodeSniffer for static analysis, contains a critical arbitrary code execution vulnerability identified as CVE-2026-65954. The issue resides in the PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey() method, which performs improper input validation when processing array keys. Specifically, the method utilizes the eval() function to determine key values, allowing an attacker to inject arbitrary PHP code within a maliciously crafted array key.
This vulnerability impacts any linting or static analysis pipeline that utilizes PHP_CodeSniffer with rulesets extending the vulnerable AbstractArrayDeclarationSniff class. Notable examples of affected downstream sniffs include Universal.Arrays.DuplicateArrayKey and Universal.Arrays.MixedArrayKeyTypes from the PHPCSExtra package. Defenders should note that this vulnerability can be triggered automatically during CI/CD processes, pull request linting, or local developer analysis if the scanned target repository contains malicious PHP code. Successful exploitation results in the execution of arbitrary commands with the privileges of the user running the PHPCS process.
Attack Chain
- Attacker crafts a malicious PHP file containing an array with a specially formatted key, such as
'system'('id'). - The target environment initiates a static analysis scan using
phpcs. - The scanning engine loads a ruleset that includes a sniff extending
AbstractArrayDeclarationSniff. - The scanner identifies the malicious array structure and triggers the
getActualArrayKey()method. - The method passes the malicious array key string directly into an
eval()call. - The PHP runtime executes the injected code within the context of the scanning host's user.
- The attacker achieves arbitrary code execution on the build server, developer workstation, or CI/CD container.
Impact
Successful exploitation allows for full command execution on the host machine running the static analysis. This poses a significant risk to CI/CD environments where pull requests from untrusted contributors are automatically scanned. If the scanning host is compromised, attackers may gain access to sensitive repository secrets, pipeline environment variables, or establish persistence within the development infrastructure.
Recommendation
- Upgrade PHPCSUtils to version 1.2.3 or later immediately to resolve CVE-2026-65954.
- If an immediate upgrade is not feasible, identify and disable the affected sniffs (e.g.,
Universal.Arrays.DuplicateArrayKeyandUniversal.Arrays.MixedArrayKeyTypes) within your ruleset XML files using the<exclude>tag. - Verify the removal of affected sniffs by executing
phpcs -e --standard=/path/to/ruleset.xmlto ensure they no longer appear in the active sniff list. - Monitor CI/CD logs for processes spawning shells or making unexpected network connections initiated by the PHPCS linter.
Immediate actions
Upgrade PHPCSUtils to version 1.2.3 or later
Mitigations
Disable vulnerable sniffs via XML ruleset configuration
CVE-2026-65954