mediumVulnerability

CVE-2026-48820

### Impact `View::_getElementFileName()` does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. ### Patches Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11. ### Workarounds If developers are not using user-supplied data in element names, no action is required.

Properties

ghsa_id
GHSA-wpvj-hjcr-h3p2
severity
medium
summary
CakePHP: View::element() is missing a path containment check
epss_score
0.00258
cve_id
CVE-2026-48820
is_ghsa_only
false
ghsa_published
2026-06-26T21:00:10Z
source_url
https://github.com/advisories/GHSA-wpvj-hjcr-h3p2
epss_percentile
0.17343
ghsa_updated
2026-06-26T21:00:11Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/cakephp/cakephp

AFFECTS (1)

[Software]composer/cakephp/cakephp

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-48820 — Ninja Signal Threat Intelligence | Ninja Signal