Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist
Not in CISA KEV

CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriverGHSA-fxf7-vhh8-7vpq

Fix: cakephp/cakephp@138f2f6

GHSA-fxf7-vhh8-7vpq is a SQL Injection vulnerability in cakephp/cakephp. A fix is available for cakephp/cakephp — see the affected versions and patch details below.

Also known asCVE-2026-77635
Published
Updated
Affected
6 pkgs
Patched
6 / 6
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-fxf7-vhh8-7vpq.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs40th percentile — riskier than 40% of all scored CVEsHighest risk
0.00%0.33%0.66%0.99%0.3%0.5%0.5%Sep 26Oct 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

6 pkgs affected
🐘cakephp/cakephp🐘cakephp/cakephp🐘cakephp/cakephp🐘cakephp/database🐘cakephp/database🐘cakephp/database

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data is supplied to the jsonPath parameter. This issue is fixed in versions 5.1.10, 5.2.15, and 5.3.7.

Affected Packages

6 total 6 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistcakephp/cakephp≥ 5.3.0&&< 5.3.75.3.7composer require cakephp/cakephp:^5.3.7
🐘Packagistcakephp/cakephp≥ 5.2.0&&< 5.2.155.2.15composer require cakephp/cakephp:^5.2.15
🐘Packagistcakephp/cakephp≥ 5.1.0&&< 5.1.105.1.10composer require cakephp/cakephp:^5.1.10
🐘Packagistcakephp/database≥ 5.3.0&&< 5.3.75.3.7composer require cakephp/database:^5.3.7
🐘Packagistcakephp/database≥ 5.2.0&&< 5.2.155.2.15composer require cakephp/database:^5.2.15
🐘Packagistcakephp/database≥ 5.1.0&&< 5.1.105.1.10composer require cakephp/database:^5.1.10

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for cakephp/cakephp, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update cakephp/cakephp to 5.3.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-fxf7-vhh8-7vpq is resolved across your whole dependency graph.

  3. Workarounds

    Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs.

Frequently Asked Questions

### Impact The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter. ### Patches 5.1.10, 5.2.15, 5.3.7 ### Workarounds Don't provide user controlled data to these functions/parameters.
O3 Security · Impact-Aware SCA

Is GHSA-fxf7-vhh8-7vpq in your dependencies?

Find it across Packagist, including transitive dependencies.

CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL…