
CVE-2026-79752-Disclosure-Paket für CakePHP 5.2.13 SQL-Injection über FunctionsBuilder::cast, mit einem Python-PoC-Skript und Docker-Lab zur autorisierten Reproduktion.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-79752
CakePHP 5.2.13 — cakephp
CakePHP ist ein Rapid-Development-Framework für PHP. Vor 4.5.12, 4.6.5, 5.1.9, 5.2.14 und 5.3.7 akzeptieren FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart und FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php benutzergesteuerte dataType-, part- oder unit-Werte und bauen sie als unescaped strukturelle Fragmente in das generierte SQL ein. Eine Anwendung, die nicht vertrauenswürdige Eingaben an diese Parameter übergibt, kann SQL-Injection mit Auswirkungen auf Vertraulichkeit, Integrität und Verfügbarkeit entsprechend den Berechtigungen der Datenbankverbindung ermöglichen. Dieses Problem ist in den Versionen 4.5.12, 4.6.5, 5.1.9, 5.2.14 und 5.3.7 behoben.
| CVE | CVE-2026-79752 · CVE.org |
| CWE | CWE-89 |
| CVSS | Kritisch: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Produkt | CakePHP |
| Betroffen | 5.2.x bis 5.2.13 (auch 4.5.x < 4.5.12, 4.6.x < 4.6.5, 5.1.x < 5.1.9, 5.3.x < 5.3.7) |
| Gepatcht | 5.2.14, 5.3.7, 5.1.9, 4.6.5, 4.5.12 |
| Auth | keine (siehe Source Map) |
| Lizenz | GNU Affero GPL v3.0 |
| Lab | nur 127.0.0.1 · Vendor/Client-Disclosure-Paket, kein Scanner |
cast() $dataType ist der Sink. HTTP ist GET /?type= in der Lab-App, keine WP-Route.
GET/?type=GET /?type=<injizierter SQL-Typ>FunctionsBuilder::cast fügt Typ als Literal einSQLite führt CAST(body AS ...) ausnotes.body POCWitness79752 im HTTP-BodyPOCWitness79752 im HTTP-Body UND die sql=-Zeile zeigt das injizierte Fragment (nicht nur CAST(body AS TEXT)).
Zuerst dies tun: Aktualisieren Sie CakePHP auf 5.2.14 (oder 5.3.7 / 5.1.9 / 4.6.5 / 4.5.12). Advisory: GHSA-vjqc-q4mp-2rvf.
Nach dem Upgrade verifizieren
CVE-2026-79752-Abraxas-Labs.py erneut gegen den gepatchten Build aus: der zugeordnete Witness darf nicht erscheinen.Wenn Sie nicht sofort aktualisieren können
Zielen Sie nur auf http://127.0.0.1:8088 (oder das von Ihnen gebundene Loopback). Richten Sie dieses Skript nicht auf das Internet.
python3 CVE-2026-79752-Abraxas-Labs.py
Erfolg ist der Witness oben im Response-Body. Generisches 200-HTML ist es nicht.
Loopback-Stack zur Reproduktion. Offizielle Images, sofern nicht ein Dockerfile in diesem Ordner aus dem Quellcode baut.
cd lab
docker compose up --force-recreate
Binden Sie den verwundbaren Produkt-Tree neben Compose ein, wenn die YAML ein lokales Verzeichnis mountet (Plugin-Zip / Source-Tag aus der Versionstabelle). Veröffentlichen Sie nichts außer 127.0.0.1.
github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0
github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e
github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676
github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d
github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45
github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf
github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-79752 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-79752`
- CWE: CWE-89
- published: 2026-09-17T15:16:51.673
## NVD description
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
## MITRE description
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
## Affected
- cakephp cakephp < 4.5.12 affected, >= 4.6.0, < 4.6.5 affected, >= 5.0.0, < 5.1.9 affected, >= 5.2.0, < 5.2.14 affected, >= 5.3.0, < 5.3.7 affected
- OSV:
## References (JSON sources only)
- https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0
- https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e
- https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676
- https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d
- https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45
- https://github.com/cakephp/cakephp/pull/19520
- https://github.com/cakephp/cakephp/pull/19528
- https://github.com/cakephp/cakephp/releases/tag/4.5.12
- https://github.com/cakephp/cakephp/releases/tag/4.6.5
- https://github.com/cakephp/cakephp/releases/tag/5.1.9
- https://github.com/cakephp/cakephp/releases/tag/5.2.14
- https://github.com/cakephp/cakephp/releases/tag/5.3.7
- https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-79752
- https://github.com/advisories/GHSA-vjqc-q4mp-2rvf
- https://github.com/cakephp/cakephp/releases/tag/5.1.8
## GitHub advisory
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
### Impact
The `FunctionsBuilder::cast($field, $dataType)`, `extract($part, $expr)`, `datePart($part, $expr)`, `dateAdd($expr, $value, $unit)` methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters.
### Patches
5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes
### Workarounds
Don't provide user controlled data to these functions/parameters.
## OSV
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed i
Dieses Disclosure-Paket ist unter der GNU Affero General Public License v3.0 lizenziert. Siehe LICENSE.
Dieses Paket ist für den Vendor, den Site-Eigentümer und lizenzierte Labs. Das Skript kommuniziert mit 127.0.0.1. Die Verwendung gegen Systeme, die Ihnen nicht gehören, ist von Abraxas Labs nicht autorisiert. Keine Gewährleistung.