{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cakephp-5.1.x-5.2.x-5.3.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-77635"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cakephp (5.1.x, 5.2.x, 5.3.x)","database (5.1.x, 5.2.x, 5.3.x)","CakePHP (4.5.0-4.5.11, 4.6.0-4.6.4, 5.0.0-5.1.8, 5.2.0-5.2.13, 5.3.0-5.3.6)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["CakePHP"],"content_html":"\u003cp\u003eThe CakePHP framework contains a critical SQL injection vulnerability identified as CVE-2026-77635. The flaw exists within the \u003ccode\u003eFunctionsBuilder::jsonValue($field, $jsonPath)\u003c/code\u003e method specifically when utilizing the Postgres driver. Attackers can exploit this vulnerability by supplying malicious, user-controlled input to the \u003ccode\u003e$jsonPath\u003c/code\u003e parameter. Because the framework does not adequately sanitize this parameter before incorporating it into SQL queries sent to the PostgreSQL backend, an attacker can append arbitrary SQL commands, potentially leading to unauthorized data extraction, modification, or deletion within the database. The vulnerability affects versions 5.1.x, 5.2.x, and 5.3.x of the \u003ccode\u003ecakephp/cakephp\u003c/code\u003e and \u003ccode\u003ecakephp/database\u003c/code\u003e packages.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated or authenticated attackers to perform unauthorized database operations, which may lead to full database compromise, exfiltration of sensitive application data, or remote code execution depending on the database configuration and permissions. All applications using the affected CakePHP versions with a PostgreSQL backend are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized remediation steps include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003ecakephp/cakephp\u003c/code\u003e and \u003ccode\u003ecakephp/database\u003c/code\u003e packages to versions 5.1.10, 5.2.15, or 5.3.7 or later to address CVE-2026-77635.\u003c/li\u003e\n\u003cli\u003eAudit application codebases for instances where user-supplied input is directly passed to the \u003ccode\u003e$jsonPath\u003c/code\u003e parameter of \u003ccode\u003eFunctionsBuilder::jsonValue()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and allowlisting for any data intended for database query parameters until patching can be completed.\u003c/li\u003e\n\u003cli\u003eReview database query logs for unusual syntax, such as SQL comments, union operators, or concatenation patterns originating from web application controllers that interface with the affected methods.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T21:53:09Z","date_published":"2026-09-08T21:49:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cakephp-sql-injection/","summary":"The CakePHP framework contains an SQL injection vulnerability in the FunctionsBuilder::jsonValue() method when using the Postgres driver, allowing unauthorized database command execution via user-controlled jsonPath input.","title":"SQL Injection in CakePHP FunctionsBuilder","url":"https://feed.craftedsignal.io/briefs/2026-09-cakephp-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cakephp (5.1.x, 5.2.x, 5.3.x)","version":"https://jsonfeed.org/version/1.1"}