<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PHPCSUtils (&gt;= 1.0.0-Alpha1, &lt; 1.2.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/phpcsutils--1.0.0-alpha1--1.2.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:19:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/phpcsutils--1.0.0-alpha1--1.2.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>PHPCSUtils Arbitrary Code Execution via AbstractArrayDeclarationSniff</title><link>https://feed.craftedsignal.io/briefs/2026-09-phpcsutils-rce/</link><pubDate>Tue, 29 Sep 2026 22:19:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-phpcsutils-rce/</guid><description>PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 are vulnerable to remote code execution due to insecure use of eval() within the AbstractArrayDeclarationSniff::getActualArrayKey() method.</description><content:encoded><![CDATA[<p>PHPCSUtils, a utility library used by PHP_CodeSniffer for static analysis, contains a critical arbitrary code execution vulnerability identified as CVE-2026-65954. The issue resides in the <code>PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()</code> method, which performs improper input validation when processing array keys. Specifically, the method utilizes the <code>eval()</code> function to determine key values, allowing an attacker to inject arbitrary PHP code within a maliciously crafted array key.</p>
<p>This vulnerability impacts any linting or static analysis pipeline that utilizes PHP_CodeSniffer with rulesets extending the vulnerable <code>AbstractArrayDeclarationSniff</code> class. Notable examples of affected downstream sniffs include <code>Universal.Arrays.DuplicateArrayKey</code> and <code>Universal.Arrays.MixedArrayKeyTypes</code> from the PHPCSExtra package. Defenders should note that this vulnerability can be triggered automatically during CI/CD processes, pull request linting, or local developer analysis if the scanned target repository contains malicious PHP code. Successful exploitation results in the execution of arbitrary commands with the privileges of the user running the PHPCS process.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious PHP file containing an array with a specially formatted key, such as <code>'system'('id')</code>.</li>
<li>The target environment initiates a static analysis scan using <code>phpcs</code>.</li>
<li>The scanning engine loads a ruleset that includes a sniff extending <code>AbstractArrayDeclarationSniff</code>.</li>
<li>The scanner identifies the malicious array structure and triggers the <code>getActualArrayKey()</code> method.</li>
<li>The method passes the malicious array key string directly into an <code>eval()</code> call.</li>
<li>The PHP runtime executes the injected code within the context of the scanning host's user.</li>
<li>The attacker achieves arbitrary code execution on the build server, developer workstation, or CI/CD container.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full command execution on the host machine running the static analysis. This poses a significant risk to CI/CD environments where pull requests from untrusted contributors are automatically scanned. If the scanning host is compromised, attackers may gain access to sensitive repository secrets, pipeline environment variables, or establish persistence within the development infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade PHPCSUtils to version 1.2.3 or later immediately to resolve CVE-2026-65954.</li>
<li>If an immediate upgrade is not feasible, identify and disable the affected sniffs (e.g., <code>Universal.Arrays.DuplicateArrayKey</code> and <code>Universal.Arrays.MixedArrayKeyTypes</code>) within your ruleset XML files using the <code>&lt;exclude&gt;</code> tag.</li>
<li>Verify the removal of affected sniffs by executing <code>phpcs -e --standard=/path/to/ruleset.xml</code> to ensure they no longer appear in the active sniff list.</li>
<li>Monitor CI/CD logs for processes spawning shells or making unexpected network connections initiated by the PHPCS linter.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>static-analysis</category><category>supply-chain</category></item></channel></rss>