PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey() (CVE-2026-65954) | HOL Guard CVE