PT-2026-79456 · Phalcon · Cphalcon

CVE-2026-59989

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Phalcon versions prior to 5.16.0
Description The resolveFilter function in phalcon/Mvc/View/Engine/Volt/Compiler.zep constructs the join filter by inserting raw separator and array token values into generated PHP without using the expression() function. An attacker capable of influencing the Volt template source can use quote-breaking content in a join argument to inject PHP into the compiled cache file, which is then executed when PhalconMvcViewEngineVolt::render() loads the template.
Recommendations Update to version 5.16.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59989
GHSA-HRWP-4HH9-C8R8

Affected Products

Cphalcon