Vendor
The mtdowling/jmespath.php library contains a critical code injection vulnerability, CVE-2026-54133, allowing attackers to execute arbitrary PHP code when untrusted JMESPath expressions are processed by the CompilerRuntime.