criticalVulnerability

CVE-2026-77635

### Impact The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter. ### Patches 5.1.10, 5.2.15, 5.3.7 ### Workarounds Don't provide user controlled data to these functions/parameters.

Properties

ghsa_id
GHSA-fxf7-vhh8-7vpq
severity
critical
summary
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
epss_score
0.00294
cve_id
CVE-2026-77635
is_ghsa_only
false
ghsa_published
2026-09-08T20:56:41Z
source_url
https://github.com/advisories/GHSA-fxf7-vhh8-7vpq
epss_percentile
0.2165
ghsa_updated
2026-09-08T20:56:41Z

Related Entities (7)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]composer/cakephp/cakephp
[Software]composer/cakephp/database

AFFECTS (2)

[Software]composer/cakephp/cakephp
[Software]composer/cakephp/database

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77635 — Ninja Signal Threat Intelligence | Ninja Signal