THREAT OPS › Threat News › [GHSA] GHSA-pcw8-m77r-2528 (critical) — jmespath.php has CompilerRuntime code injection via unescaped function names
[GHSA] GHSA-pcw8-m77r-2528 (critical) — jmespath.php has CompilerRuntime code injection via unescaped function names
GHSA-pcw8-m77r-2528 Severity: critical CVE: CVE-2026-54133
jmespath.php has CompilerRuntime code injection via unescaped function names
## Impact
`mtdowling/jmespath.php` can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without
Indicators of compromise
- CVE-2026-54133cve
Original source: https://github.com/advisories/GHSA-pcw8-m77r-2528