THREAT OPS › Threat News › [GHSA] GHSA-hrwp-4hh9-c8r8 (critical) — Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
[GHSA] GHSA-hrwp-4hh9-c8r8 (critical) — Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
GHSA-hrwp-4hh9-c8r8 Severity: critical CVE: CVE-2026-59989
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
## Summary
The Volt template compiler in Phalcon generates the PHP for the `join` filter by string-concatenating the filter's **raw template-literal argument bytes** with no escaping. The separator literal is dropped verbatim between two single quote
MITRE ATT&CK techniques
- Template InjectionT1221
Indicators of compromise
- CVE-2026-59989cve
Original source: https://github.com/advisories/GHSA-hrwp-4hh9-c8r8