THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pcw8-m77r-2528 (critical) — jmespath.php has CompilerRuntime code injection via unescaped function names

[GHSA] GHSA-pcw8-m77r-2528 (critical) — jmespath.php has CompilerRuntime code injection via unescaped function names

medgithub_advisoriesPublished 2026-08-18

GHSA-pcw8-m77r-2528 Severity: critical CVE: CVE-2026-54133

jmespath.php has CompilerRuntime code injection via unescaped function names

## Impact

`mtdowling/jmespath.php` can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pcw8-m77r-2528