GHSA-fxf7-vhh8-7vpq
Dashboard / Vulnerabilities / GHSA-fxf7-vhh8-7vpq
Summary: CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
Details: ### Impact The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter. ### Patches 5.1.10, 5.2.15, 5.3.7 ### Workarounds Don't provide user controlled data to these functions/parameters.
References: https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq, https://nvd.nist.gov/vuln/detail/CVE-2026-77635, https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3, https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55, https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f, https://github.com/cakephp/cakephp, https://github.com/cakephp/cakephp/releases/tag/5.1.10, https://github.com/cakephp/cakephp/releases/tag/5.2.15, https://github.com/cakephp/cakephp/releases/tag/5.3.7
Affected packages
Package
Name: cakephp/cakephp
Purl: pkg:composer/cakephp/cakephp
Affected ranges
Type: ECOSYSTEM
Events:
