THREAT OPS › Threat News › [GHSA] GHSA-p46m-g734-vpc4 (medium) — cakephp/debug_kit: MailPreview contains unsafe reflection
[GHSA] GHSA-p46m-g734-vpc4 (medium) — cakephp/debug_kit: MailPreview contains unsafe reflection
GHSA-p46m-g734-vpc4 Severity: medium CVE: CVE-2026-54614
cakephp/debug_kit: MailPreview contains unsafe reflection
### Impact
The `MailPreview` feature of debugkit is vulnerable to arbitrary constructor execution. For an application to be vulnerable the following conditions must be true:
1. `debug` mode must be enabled. 2. The hostname must match a 'local' domain or be in an allowlist.
### Pa
Indicators of compromise
- CVE-2026-54614cve
Original source: https://github.com/advisories/GHSA-p46m-g734-vpc4