
Disclosure pack and Python PoC for CVE-2026-77635, an unauthenticated SQL injection in CakePHP's jsonValue() with PostgresDriver, including a loopback Docker lab.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-77635
CakePHP 5.2.13 - cakephp
I am @abraxas_null. Loopback lab. The client is CVE-2026-77635-Abraxas-Labs.py.
JSON_VALUE is not bound. FunctionsBuilder::jsonValue() with PostgresDriver rewrites to JSONB_PATH_QUERY and puts $jsonPath through quoteIdentifier. That is not a bound parameter. Lab GET /?path=. Needs PostgreSQL. Not WordPress. Sibling of CVE-2026-79752. Fixed in 5.2.15, 5.1.10, 5.3.7.
| CVE | CVE-2026-77635 · CVE.org |
| CWE | CWE-89 |
| CVSS | Critical: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| Product | CakePHP |
| Affected | 5.2.x through 5.2.13 (also 5.1.x < 5.1.10, 5.3.x < 5.3.7) |
| Patched | 5.2.15, 5.1.10, 5.3.7 |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
An application that takes the json path from the request lets the caller close the jsonpath and UNION secret. An application that hard-codes '$.x' is fine. This is CakePHP putting a caller-supplied path into SQL, not "Postgres jsonpath is unsafe."
The GHSA named jsonValue on PostgresDriver. I read the transform, then built a lab that passes GET into it.
Default GET / is $.missing and []. Connection refused is Postgres not ready. Inject GET must put a fragment in sql= and return POCWitness77635.
Wrong turns: SQLite image (this transform is Postgres); witness string only in PHP source; no sql= fragment because the path never left the builder.
Port 8088. cakephp/database 5.2.13 plus PostgreSQL. notes.secret = POCWitness77635.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-77635-Abraxas-Labs.py
Witness: POCWitness77635 in the JSON and the injected fragment in sql=. Empty $.missing rows are not it.
Ways to lose without learning anything:
Update CakePHP to 5.2.15 (or 5.1.10 / 5.3.7). Re-run CVE-2026-77635-Abraxas-Labs.py against the patched build: the injected fragment must not appear in sql=.
github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3
github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55
github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f
github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq
github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77635.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.