criticalVulnerability

CVE-2026-79752

### Impact The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $expr)`, `datePart($part, $expr)`, `dateAdd($expr, $value, $unit)` methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters. ### Patches 5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes ### Workarounds Don't provide user controlled data to these functions/parameters.

Properties

ghsa_id
GHSA-vjqc-q4mp-2rvf
severity
critical
summary
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
cve_id
CVE-2026-79752
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:28:14Z
source_url
https://github.com/advisories/GHSA-vjqc-q4mp-2rvf
ghsa_updated
2026-09-17T20:28:17Z

Related Entities (6)

AFFECTS (2)

[Software]composer/cakephp/cakephp
[Software]composer/cakephp/database

VULNERABLE_TO (2)

[Software]composer/cakephp/cakephp
[Software]composer/cakephp/database

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79752 — Ninja Signal Threat Intelligence | Ninja Signal