PT-2026-95007 · Cakephp+1 · Cakephp+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
A flaw in the background job dispatch mechanism allows remote code execution with the privileges of the web user. The issue occurs because background job arguments are passed directly as the
argv of the CakePHP console process. The ShellDispatcher:: parsePaths() function scans argv for path switches such as -app, --app, -working, --working, -root, --root, -webroot, and --webroot, using the subsequent element as the application root. Specifically, the 'events/contact' endpoint forwards the message and person fields into job arguments without validation. An attacker can set the person field to a reserved switch and the message field to a phar:// URI (a PHP archive wrapper) pointing to a malicious archive. This causes the CakePHP bootstrap to include Config/core.php from the archive, executing arbitrary PHP code. This allows for data exfiltration, persistence, and lateral movement within the host.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cakephp
Misp