THREAT OPS › Threat News › [GHSA] GHSA-fxf7-vhh8-7vpq (critical) — CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
[GHSA] GHSA-fxf7-vhh8-7vpq (critical) — CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
GHSA-fxf7-vhh8-7vpq Severity: critical CVE: CVE-2026-77635
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
### Impact The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter.
### Patches 5.1.10, 5.2.15, 5.3.7
### Workarounds Don't
Indicators of compromise
- CVE-2026-77635cve
Original source: https://github.com/advisories/GHSA-fxf7-vhh8-7vpq