Answer in brief
CVE-2026-65954 records a High severity (CVSS 8.6) vulnerability in PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey(). The current sources do not mark it as known exploited. The current feed maps phpcsstandards/phpcsutils (composer), phpcsstandards/phpcsutils (packagist). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps phpcsstandards/phpcsutils (composer), phpcsstandards/phpcsutils (packagist). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| phpcsstandards/phpcsutilscomposer | >=1.0.0-alpha1,<1.2.3 | 1.2.3 |
| phpcsstandards/phpcsutilspackagist | >=1.0.0-alpha1 <1.2.3 | 1.2.3 |
Published upstream
Sep 29, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
### Impact PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()`. The vulnerable method is reached by any sniff that extends `AbstractArrayDeclarationSniff` and calls `getActualArrayKey()`. Running PHPCS over untrusted PHP code through such a sniff, for example, in a CI pipeline that lints pull requests, or on a developer machine reviewing third-party code, could lead to arbitrary command execution on the scanning host. The vulnerability happens when the method determines the value of an array key using `eval()`. A maliciously crafted array key such as `'system'('id')` would be executed when the code was scanned. ### Known attack vectors Known code paths that reach the vulnerable method include the following PHPCSExtra sniffs: - `Universal.Arrays.DuplicateArrayKey` - `Universal.Arrays.MixedArrayKeyTypes` Other packages that call `AbstractArrayDeclarationSniff::getActualArrayKey()` may also be vulnerable. ### Patches This issue has been fixed in PHPCSUtils 1.2.3. We recommend all users upgrade to 1.2.3 or later. ### Workaround Users who cannot upgrade immediately can disable the sniffs that reach the vulnerable method by adding `<exclude>` tags to their custom ruleset (replace the placeholder standard and sniff names with the ones used in your setup): ```xml <rule ref="Standard"> <exclude name="Standard.Category.SniffName"/> </rule> ``` For example, to disable the two PHPCSExtra sniffs listed under "Known attack vectors": ```xml <rule ref="Universal"> <exclude name="Universal.Arrays.DuplicateArrayKey"/> <exclude name="Universal.Arrays.MixedArrayKeyTypes"/> </rule> ``` To verify that the sniffs have been disabled, run PHPCS with the `-e` flag, which lists all the sniffs a standard will run. The excluded sniffs should no longer appear in the output: ``` phpcs -e --standard=/path/to/ruleset.xml ``` ### Credits Many thanks to [@rodrigoprimo](https://github.com/rodrigoprimo) for responsibly disclosing this vulnerability. ### How can I report a security bug? Please report security vulnerabilities privately via [the "Security and quality" tab on the PHPCSUtils repository](https://github.com/PHPCSStandards/PHPCSUtils/security).
Quoted source text, attributed separately from HOL analysis.