
CVE-2026-79752 disclosure pack for CakePHP 5.2.13 SQL injection via FunctionsBuilder::cast, with a Python PoC script and Docker lab for authorized reproduction.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-79752
CakePHP 5.2.13 - cakephp
I am @abraxas_null. Loopback lab. The client is CVE-2026-79752-Abraxas-Labs.py.
CAST AS literal. FunctionsBuilder::cast (and extract / datePart / dateAdd) splices caller dataType / part / unit into SQL as unescaped structure. Lab GET /?type= into cast('body', $_GET['type']) on sqlite. Not WordPress. Sibling of CVE-2026-77635 (jsonValue / Postgres). Fixed in 5.2.14, 5.3.7, 5.1.9, 4.6.5, 4.5.12.
| CVE | CVE-2026-79752 · CVE.org |
| CWE | CWE-89 |
| CVSS | Critical: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Product | CakePHP |
| Affected | 5.2.x through 5.2.13 (also 4.5.x < 4.5.12, 4.6.x < 4.6.5, 5.1.x < 5.1.9, 5.3.x < 5.3.7) |
| Patched | 5.2.14, 5.3.7, 5.1.9, 4.6.5, 4.5.12 |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
An application that passes request data into func()->cast(..., $type) (or the other three) lets the caller close the CAST and UNION whatever they want. The lab leaks notes.body. That is SQL injection in the CakePHP query builder, not in Postgres jsonpath.
The GHSA named four methods. I read cast, then built a sqlite app that passes GET into it.
Default GET / is CAST(body AS INTEGER) and [{"v":0}]. That is the product working. Inject GET must put a fragment in sql= and return POCWitness79752.
Wrong turns: composer 500 because the image skipped composer install; grepping the witness out of PHP source; sql= still only CAST(body AS INTEGER) after the inject GET.
Port 8088. cakephp/database 5.2.13. Lab app under lab/lab-www. sqlite notes.body = POCWitness79752.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-79752-Abraxas-Labs.py
Witness: POCWitness79752 in the HTTP body and sql= shows the injected fragment, not only CAST(body AS INTEGER).
Ways to lose without learning anything:
sql=Update CakePHP to 5.2.14 (or 5.3.7 / 5.1.9 / 4.6.5 / 4.5.12). Re-run CVE-2026-79752-Abraxas-Labs.py against the patched build: the injected fragment must not appear in sql=.
github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0
github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e
github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676
github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d
github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45
github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf
github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.