THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p46m-g734-vpc4 (medium) — cakephp/debug_kit: MailPreview contains unsafe reflection

[GHSA] GHSA-p46m-g734-vpc4 (medium) — cakephp/debug_kit: MailPreview contains unsafe reflection

medgithub_advisoriesPublished 2026-08-26

GHSA-p46m-g734-vpc4 Severity: medium CVE: CVE-2026-54614

cakephp/debug_kit: MailPreview contains unsafe reflection

### Impact

The `MailPreview` feature of debugkit is vulnerable to arbitrary constructor execution. For an application to be vulnerable the following conditions must be true:

1. `debug` mode must be enabled. 2. The hostname must match a 'local' domain or be in an allowlist.

### Pa

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p46m-g734-vpc4