← العودة للجدول
CVE-2026-54133
CVE-2026-54133 — jmespath.php allows users to use JMESPath, software for declaratively specifying
📅 2026-06-12
🔴 Critical 🔥 No NVD Exploit Web CVSS 9.8

📋 الوصف الكامل

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into gener

💻 الأنظمة المتأثرة

PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-54133

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2.9.1

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←