criticalVulnerability
CVE-2026-79752
### Impact The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $expr)`, `datePart($part, $expr)`, `dateAdd($expr, $value, $unit)` methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters. ### Patches 5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes ### Workarounds Don't provide user controlled data to these functions/parameters.
Properties
- ghsa_id
- GHSA-vjqc-q4mp-2rvf
- severity
- critical
- summary
- CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
- cve_id
- CVE-2026-79752
- signal_observed_at
- 2026-09-17T21:32:39+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-17T20:28:14Z
- source_url
- https://github.com/advisories/GHSA-vjqc-q4mp-2rvf
- ghsa_updated
- 2026-09-17T20:28:17Z
Related Entities (6)
AFFECTS (2)
→[Software]composer/cakephp/cakephp
→[Software]composer/cakephp/database
VULNERABLE_TO (2)
←[Software]composer/cakephp/cakephp
←[Software]composer/cakephp/database
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph