
CVE-2026-77635の開示パックとPython PoC。PostgresDriver使用時のCakePHPのjsonValue()における未認証SQLインジェクションで、ループバックDockerラボを含みます。
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-77635
CakePHP 5.2.13 — cakephp
CakePHP は PHP 向けの高速開発フレームワークです。各リリースラインのバージョン 5.1.10、5.2.15、5.3.7 より前では、PostgresDriver を使用した FunctionsBuilder::jsonValue() において、ユーザー制御のデータが jsonPath パラメータに渡された場合に SQL インジェクションが発生する脆弱性があります。この問題はバージョン 5.1.10、5.2.15、5.3.7 で修正されています。
| CVE | CVE-2026-77635 · CVE.org |
| CWE | CWE-89 |
| CVSS | Critical: 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| Product | CakePHP |
| Affected | 5.2.x 5.2.13 まで (また 5.1.x < 5.1.10、5.3.x < 5.3.7) |
| Patched | 5.2.15、5.1.10、5.3.7 |
| Auth | なし (ソースマップを参照) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 のみ · ベンダー/クライアント開示パックであり、スキャナーではありません |
jsonValue の $jsonPath がシンクです。HTTP はラボアプリの GET /?path= です。
GET/?path=GET /?path=<injected jsonPath>PostgresDriver quoteIdentifier into JSONB_PATH_QUERYSELECT leaks notes.secretHTTP ボディ内の POCWitness77635 および sql= にインジェクションされたフラグメントが含まれます。
まずこれを実行: CakePHP を 5.2.15 (または 5.1.10 / 5.3.7) に更新してください。アドバイザリ: GHSA-fxf7-vhh8-7vpq。
アップグレード後の確認
CVE-2026-77635-Abraxas-Labs.py を再実行します。マッピングされた witness が出現しないことを確認してください。すぐに更新できない場合
必ず http://127.0.0.1:8088 (またはバインドしたループバック) のみを対象にしてください。このスクリプトをインターネットに向けないでください。
python3 CVE-2026-77635-Abraxas-Labs.py
成功とは、レスポンスボディに上記の witness が含まれることです。一般的な 200 HTML は成功ではありません。
再現に使用したループバックスタック。このフォルダ内の Dockerfile がソースからビルドする場合を除き、公式イメージを使用します。
cd lab
docker compose up --force-recreate
YAML がローカルディレクトリ (バージョン表のプラグイン zip / ソースタグ) をマウントする場合は、脆弱な製品ツリーを Compose の隣にバインドしてください。127.0.0.1 以外には何も公開しないでください。
github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3
github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55
github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f
github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq
github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77635.json
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-77635 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-77635`
- CWE: CWE-89
- published: 2026-08-24T21:17:48.457
## NVD description
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
## MITRE description
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
## Affected
- cakephp cakephp >= 5.1.0, < 5.1.10 affected, >= 5.2.0, < 5.2.15 affected, >= 5.3.0, < 5.3.7 affected
- cakephp cakephp/database >= 5.1.0, < 5.1.10 affected, >= 5.2.0, < 5.2.15 affected, >= 5.3.0, < 5.3.7 affected
- OSV:
## References (JSON sources only)
- https://github.com/cakephp/cakephp/commit/138f2f61486532c29ee4d106da2a9848c1ff1ab3
- https://github.com/cakephp/cakephp/commit/489a40fb7c6e597af33fe0f7264047afccb90d55
- https://github.com/cakephp/cakephp/commit/9f1ad970a3b72293d4a37e694276645f804e819f
- https://github.com/cakephp/cakephp/releases/tag/5.1.10
- https://github.com/cakephp/cakephp/releases/tag/5.2.15
- https://github.com/cakephp/cakephp/releases/tag/5.3.7
- https://github.com/cakephp/cakephp/security/advisories/GHSA-fxf7-vhh8-7vpq
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77635.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-77635
- https://github.com/advisories/GHSA-fxf7-vhh8-7vpq
## GitHub advisory
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
### Impact
The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter.
### Patches
5.1.10, 5.2.15, 5.3.7
### Workarounds
Don't provide user controlled data to these functions/parameters.
## OSV
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.
この開示パックは GNU Affero General Public License v3.0 の下でライセンスされています。LICENSE を参照してください。
このパックはベンダー、サイト所有者、および許可されたラボ向けです。スクリプトは 127.0.0.1 と通信します。所有していないシステムに対して使用することは Abraxas Labs によって許可されていません。保証はありません。