CakePHP disclosed and patched CVE-2026-77635, a SQL injection flaw in FunctionsBuilder::jsonValue() when used with the PostgreSQL driver. The weakness allowed query manipulation if attacker-controlled input was passed to the jsonPath parameter, affecting CakePHP and cakephp/database versions >= 5.1.0, < 5.1.10, >= 5.2.0, < 5.2.15, and >= 5.3.0, < 5.3.7. The issue is tracked as CWE-89 and carries a CVSS v4 assessment indicating network exploitability, low attack complexity, no privileges required, and high confidentiality and integrity impact.
Maintainers released fixes across supported branches in commits for the 5.2.x, 5.3.x, and 5.x lines, changing how PostgreSQL-specific jsonValue expressions are transformed. Regression tests added with the patches show legitimate JSON path extraction still works, while malicious path payloads now fail with a PostgreSQL syntax error surfaced as a QueryException instead of enabling successful query manipulation. The fix was credited to reporter Himanshu Anand, and patched releases include 5.1.10, 5.2.15, and 5.3.7.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CERT-PY reported CVE-2026-77634, a header injection vulnerability in CakePHP that could let attackers inject additional code into an email header via user-controlled data. The notice says versions before 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 are affected and recommends upgrading to fixed releases.
A CVE entry recorded the issue as CVE-2026-77635, describing an SQL injection vulnerability in CakePHP and cakephp/database when user-controlled data is passed to jsonPath with PostgresDriver. The record also states GitHub published advisory GHSA-fxf7-vhh8-7vpq and lists affected and fixed version ranges.
On July 16, 2026, CakePHP also committed the PostgreSQL jsonValue fix to its 5.2.x branch, associated with version 5.2.15. The change removed unsafe handling of user-controlled JSON path expressions and added a regression test for malicious payloads.
On July 16, 2026, CakePHP committed the same PostgreSQL jsonValue fix to its 5.1.x branch, associated with release 5.1.10. The regression test verified benign JSON path extraction still worked while malicious input now triggered a QueryException instead of enabling query manipulation.
On July 9, 2026, CakePHP committed a fix for a query-manipulation weakness in FunctionsBuilder::jsonValue() for the PostgreSQL driver. The patch changed PostgreSQL JSON value transformation logic, added a regression test, and credited Himanshu Anand for reporting the issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.