CVE-2026-54133 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-54133 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-54133 is a critical remote code execution issue in mtdowling/jmespath.php affecting applications that evaluate attacker-controlled JMESPath expressions with JmesPath\CompilerRuntime or with JmesPath\search() while JP_PHP_COMPILE is enabled. In vulnerable flows, a crafted expression can be written into generated PHP cache files and then executed by the application, giving an attacker arbitrary PHP execution with the privileges of the web process.

This is especially relevant for solo developers and small teams using JMESPath for filtering, querying, or transforming user-supplied data. The default AstRuntime path is not affected unless PHP compilation is explicitly enabled.

Immediate Action

  • Upgrade immediately to mtdowling/jmespath.php 2.9.1+. If you cannot patch today, treat the service as high risk and move to the workaround below.
  • Disable PHP compilation: turn off JP_PHP_COMPILE and stop using JmesPath\CompilerRuntime for any untrusted expression input.
  • Restrict expression sources: do not accept raw JMESPath strings from users, API clients, query parameters, or stored content until patched.
  • Clear compiled cache directories after remediation to remove any potentially malicious generated PHP files.
  • Review logs and endpoints that accept JMESPath expressions for unusual payloads, especially non-identifier function names or unexpected syntax.
  • Vendor advisory: see vendor advisory / release notes for the patched release and any follow-up guidance.

Affected Versions

  • mtdowling/jmespath.php@<=2.9.0 vulnerable; upgrade to 2.9.1+
  • JmesPath\CompilerRuntime usage with attacker-controlled expressions is vulnerable on affected versions
  • JmesPath\search() is vulnerable only when JP_PHP_COMPILE is enabled on affected versions
  • AstRuntime default path is not affected unless compilation is enabled

Resolution Guide

PHP / Composer

composer require mtdowling/jmespath.php:^2.9.1
composer update mtdowling/jmespath.php
composer show mtdowling/jmespath.php

Hardening: disable compilation for untrusted input

<?php
use JmesPath\Env as JmesPathEnv;

// Disable compiled PHP generation for untrusted expressions
putenv('JP_PHP_COMPILE=0');

// Prefer the default AstRuntime for user-controlled expressions
$result = \JmesPath\search($expression, $data);

Minimal code fix pattern

<?php
use JmesPath\CompilerRuntime;

// Before: unsafe if $expr can be influenced by users
// $runtime = new CompilerRuntime();

// After: use AstRuntime/default search path for untrusted expressions
$result = \JmesPath\search($expr, $data);

// If you must use compilation, only allow trusted, pre-vetted expressions

npm / yarn / pnpm — not applicable to this PHP package, but if your app bundles a service that mirrors the same logic, update the equivalent dependency there.

pip / pipx — not applicable to this PHP package.

Maven / Gradle — not applicable to this PHP package.

Linux package managers — if your deployment packages the app via OS packages, redeploy the application after updating Composer dependencies:

# Debian/Ubuntu
sudo apt-get update
sudo apt-get install --only-upgrade <your-app-package>

# RHEL/CentOS/Fedora
sudo yum update <your-app-package>
# or
sudo dnf upgrade <your-app-package>

Docker

# Rebuild using the patched Composer dependency
docker build --no-cache -t your-app:patched .
docker run --rm your-app:patched

If you pin images, publish a new tag after rebuilding with mtdowling/jmespath.php 2.9.1+, then roll the deployment forward.

Detection & Verification

Check installed version

composer show mtdowling/jmespath.php
composer why mtdowling/jmespath.php

Search for risky usage

grep -RIn "CompilerRuntime\|JP_PHP_COMPILE\|JmesPath\\search" .

Look for user-controlled expressions: inspect routes, controllers, jobs, and API handlers that accept JMESPath strings from request bodies, query parameters, config fields, or database records.

Verify the fix

composer show mtdowling/jmespath.php | grep versions
php -r 'require "vendor/autoload.php"; echo class_exists("JmesPath\\CompilerRuntime") ? "loaded\n" : "missing\n";'
php -r 'echo getenv("JP_PHP_COMPILE") ?: "unset\n";'

Confirm that the installed version is 2.9.1 or later, that compiled-expression caching is disabled for untrusted input, and that no code path instantiates CompilerRuntime for user-supplied expressions.

Risk and Impact

An attacker who can influence the JMESPath expression string can trigger generation of malicious PHP code and get it executed by the application. That can lead to full compromise of the web app, theft of secrets, data tampering, lateral movement, and persistent backdoor access if the attacker can write files in the cache directory.

The blast radius depends on the PHP process privileges and what the app can reach: database credentials, API keys, internal services, and user data may all be exposed. Even small apps are at risk if they expose “advanced filter” or “query builder” features to users.

Keep reading