{"id":"ROOT-APP-COMPOSER-CVE-2026-54133","summary":"CVE-2026-54133 in mtdowling/jmespath.php - Patched by Root","details":"Root has patched CVE-2026-54133 in the mtdowling/jmespath.php package for Root:Composer. Multiple fixed versions available.","modified":"2026-07-01T18:45:05.761470449Z","published":"2026-07-01T13:18:25Z","upstream":["CVE-2026-54133"],"database_specific":{"distro":"composer","distro_version":"","severity":"CRITICAL","source":"Root"},"affected":[{"package":{"name":"mtdowling/jmespath.php","ecosystem":"Root:Composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.0-p12007001+aikido"}]}],"database_specific":{"total_fixed_versions":1,"upstream_version":"2.8.0-p12007001+aikido","source":"https://api.root.io/external/osv/ROOT-APP-COMPOSER-CVE-2026-54133.json","all_fixed_versions":["2.8.0-p12007001+aikido"],"root_patch_version":"","root_patched":true}},{"package":{"name":"rootio-mtdowling/jmespath.php","ecosystem":"Root:Composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.0-p12007001"}]}],"database_specific":{"total_fixed_versions":1,"upstream_version":"2.8.0-p12007001","all_fixed_versions":["2.8.0-p12007001"],"root_patch_version":"","root_patched":true,"source":"https://api.root.io/external/osv/ROOT-APP-COMPOSER-CVE-2026-54133.json"}}],"schema_version":"1.7.5"}