
Paquete de divulgación y PoC en Python para CVE-2026-77635, una inyección SQL no autenticada en jsonValue() de CakePHP con PostgresDriver, que incluye un laboratorio Docker en loopback.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-77635
CakePHP 5.2.13 — cakephp
CakePHP es un framework de desarrollo rápido para PHP. Antes de las versiones 5.1.10, 5.2.15 y 5.3.7 en sus respectivas líneas de lanzamiento, FunctionsBuilder::jsonValue() con PostgresDriver es vulnerable a inyección SQL cuando se suministran datos controlados por el usuario al parámetro jsonPath. Este problema está corregido en las versiones 5.1.10, 5.2.15 y 5.3.7.
| CVE | CVE-2026-77635 · CVE.org |
| CWE | CWE-89 |
| CVSS | Crítico: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| Producto | CakePHP |
| Afectado | 5.2.x hasta 5.2.13 (también 5.1.x < 5.1.10, 5.3.x < 5.3.7) |
| Parcheado | 5.2.15, 5.1.10, 5.3.7 |
| Autenticación | ninguna (ver mapa de origen) |
| Licencia | GNU Affero GPL v3.0 |
| Laboratorio | solo 127.0.0.1 · paquete de divulgación para el proveedor/cliente, no es un escáner |
jsonValue $jsonPath es el sink. HTTP es GET /?path= en la aplicación de laboratorio.
GET/?path=GET /?path=<jsonPath inyectado>PostgresDriver quoteIdentifier en JSONB_PATH_QUERYSELECT filtra notes.secretPOCWitness77635 en el cuerpo HTTP y sql= contiene el fragmento inyectado.
Haga esto primero: Actualice CakePHP a 5.2.15 (o 5.1.10 / 5.3.7). Aviso: GHSA-fxf7-vhh8-7vpq.
Verificar después de la actualización
CVE-2026-77635-Abraxas-Labs.py contra la compilación parcheada: el testigo mapeado no debe aparecer.Si no puede actualizar inmediatamente
Apunte solo a http://127.0.0.1:8088 (o al loopback que haya enlazado). No apunte este script a internet.
python3 CVE-2026-77635-Abraxas-Labs.py
El éxito es el testigo anterior en el cuerpo de la respuesta. Un 200 HTML genérico no lo es.
Pila de loopback usada para reproducir. Imágenes oficiales a menos que un Dockerfile en esta carpeta compile desde el código fuente.
cd lab
docker compose up --force-recreate
Enlace el árbol del producto vulnerable junto a Compose si el YAML monta un directorio local (zip del plugin / etiqueta de código fuente de la tabla de versiones). No publique nada excepto 127.0.0.1.
github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3
github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55
github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f
github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq
github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77635.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-77635 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-77635`
- CWE: CWE-89
- published: 2026-08-24T21:17:48.457
## NVD description
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
## MITRE description
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
## Affected
- cakephp cakephp >= 5.1.0, < 5.1.10 affected, >= 5.2.0, < 5.2.15 affected, >= 5.3.0, < 5.3.7 affected
- cakephp cakephp/database >= 5.1.0, < 5.1.10 affected, >= 5.2.0, < 5.2.15 affected, >= 5.3.0, < 5.3.7 affected
- OSV:
## References (JSON sources only)
- https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3
- https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55
- https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f
- https://github.com/cakephp/cakephp/releases/tag/5.1.10
- https://github.com/cakephp/cakephp/releases/tag/5.2.15
- https://github.com/cakephp/cakephp/releases/tag/5.3.7
- https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77635.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-77635
- https://github.com/advisories/GHSA-fxf7-vhh8-7vpq
## GitHub advisory
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
### Impact
The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter.
### Patches
5.1.10, 5.2.15, 5.3.7
### Workarounds
Don't provide user controlled data to these functions/parameters.
## OSV
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
Este paquete de divulgación está licenciado bajo la GNU Affero General Public License v3.0. Ver LICENSE.
Este paquete es para el proveedor, el propietario del sitio y laboratorios con licencia. El script se comunica con 127.0.0.1. Usarlo contra sistemas que no posee no está autorizado por Abraxas Labs. Sin garantía.