{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/phpcsutils--1.0.0-alpha1--1.2.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpcsstandards:phpcsutils:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PHPCSUtils (\u003e= 1.0.0-alpha1, \u003c 1.2.3)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","static-analysis","supply-chain"],"_cs_type":"advisory","_cs_vendors":["PHPCSStandards"],"content_html":"\u003cp\u003ePHPCSUtils, a utility library used by PHP_CodeSniffer for static analysis, contains a critical arbitrary code execution vulnerability identified as CVE-2026-65954. The issue resides in the \u003ccode\u003ePHPCSUtils\\AbstractSniffs\\AbstractArrayDeclarationSniff::getActualArrayKey()\u003c/code\u003e method, which performs improper input validation when processing array keys. Specifically, the method utilizes the \u003ccode\u003eeval()\u003c/code\u003e function to determine key values, allowing an attacker to inject arbitrary PHP code within a maliciously crafted array key.\u003c/p\u003e\n\u003cp\u003eThis vulnerability impacts any linting or static analysis pipeline that utilizes PHP_CodeSniffer with rulesets extending the vulnerable \u003ccode\u003eAbstractArrayDeclarationSniff\u003c/code\u003e class. Notable examples of affected downstream sniffs include \u003ccode\u003eUniversal.Arrays.DuplicateArrayKey\u003c/code\u003e and \u003ccode\u003eUniversal.Arrays.MixedArrayKeyTypes\u003c/code\u003e from the PHPCSExtra package. Defenders should note that this vulnerability can be triggered automatically during CI/CD processes, pull request linting, or local developer analysis if the scanned target repository contains malicious PHP code. Successful exploitation results in the execution of arbitrary commands with the privileges of the user running the PHPCS process.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious PHP file containing an array with a specially formatted key, such as \u003ccode\u003e'system'('id')\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe target environment initiates a static analysis scan using \u003ccode\u003ephpcs\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe scanning engine loads a ruleset that includes a sniff extending \u003ccode\u003eAbstractArrayDeclarationSniff\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe scanner identifies the malicious array structure and triggers the \u003ccode\u003egetActualArrayKey()\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eThe method passes the malicious array key string directly into an \u003ccode\u003eeval()\u003c/code\u003e call.\u003c/li\u003e\n\u003cli\u003eThe PHP runtime executes the injected code within the context of the scanning host's user.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary code execution on the build server, developer workstation, or CI/CD container.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full command execution on the host machine running the static analysis. This poses a significant risk to CI/CD environments where pull requests from untrusted contributors are automatically scanned. If the scanning host is compromised, attackers may gain access to sensitive repository secrets, pipeline environment variables, or establish persistence within the development infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade PHPCSUtils to version 1.2.3 or later immediately to resolve CVE-2026-65954.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, identify and disable the affected sniffs (e.g., \u003ccode\u003eUniversal.Arrays.DuplicateArrayKey\u003c/code\u003e and \u003ccode\u003eUniversal.Arrays.MixedArrayKeyTypes\u003c/code\u003e) within your ruleset XML files using the \u003ccode\u003e\u0026lt;exclude\u0026gt;\u003c/code\u003e tag.\u003c/li\u003e\n\u003cli\u003eVerify the removal of affected sniffs by executing \u003ccode\u003ephpcs -e --standard=/path/to/ruleset.xml\u003c/code\u003e to ensure they no longer appear in the active sniff list.\u003c/li\u003e\n\u003cli\u003eMonitor CI/CD logs for processes spawning shells or making unexpected network connections initiated by the PHPCS linter.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T22:19:19Z","date_published":"2026-09-29T22:19:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phpcsutils-rce/","summary":"PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 are vulnerable to remote code execution due to insecure use of eval() within the AbstractArrayDeclarationSniff::getActualArrayKey() method.","title":"PHPCSUtils Arbitrary Code Execution via AbstractArrayDeclarationSniff","url":"https://feed.craftedsignal.io/briefs/2026-09-phpcsutils-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - PHPCSUtils (\u003e= 1.0.0-Alpha1, \u003c 1.2.3)","version":"https://jsonfeed.org/version/1.1"}