{"id":"CVE-2026-79752","summary":"CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection","details":"CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.","aliases":["GHSA-vjqc-q4mp-2rvf"],"modified":"2026-09-19T03:47:23.303259353Z","published":"2026-09-17T14:49:56.936Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/4.5.12"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/4.6.5"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/5.1.9"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/5.2.14"},{"type":"WEB","url":"https://github.com/cakephp/cakephp/releases/tag/5.3.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json"},{"type":"ADVISORY","url":"https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79752"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/pull/19520"},{"type":"FIX","url":"https://github.com/cakephp/cakephp/pull/19528"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cakephp/cakephp","events":[{"introduced":"0"},{"introduced":"b8585672346c0654311c77500ce613cdf37687cc"},{"introduced":"2da6ed819f520e472ea12b011a9c7a7f39310a4a"},{"introduced":"8eb600bb67a545e2d108f9ae64146f094a39bb55"},{"introduced":"c0175d821a5e42b934ad2a11927c5c5d0e659a0d"},{"fixed":"cc9dbe1fbcb1cb6fd20eb2ebf457c9774dfa5f49"},{"fixed":"2818927cc949af84fd847d72d65edeaac581cb8b"},{"fixed":"a029afaa6879d6c9dc41c20e09f727fd767b9893"},{"fixed":"111336d93f8fb044b2b68d4526cf10876432fd2d"},{"fixed":"c0d21e0da4216d51268691af3ad803f0eecb3a11"},{"fixed":"3349584ca3a891afaff2dbc324d6b1c09fb880f0"},{"fixed":"3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e"},{"fixed":"79e1d6bc6f3a50fa01805579076a02c77370c676"},{"fixed":"8699d6f38e25fe46fcc24f2b698809948e71ad7d"},{"fixed":"ab608711674ac662af7315c5cdf1e0fbe2000e45"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"4.5.12"},{"introduced":"4.6.0"},{"fixed":"4.6.5"},{"introduced":"5.0.0"},{"fixed":"5.1.9"},{"introduced":"5.2.0"},{"fixed":"5.2.14"},{"introduced":"5.3.0"},{"fixed":"5.3.7"}]}}],"versions":["5.1.8","5.2.13","5.1.7","4.6.4","4.5.11","5.3.6","4.5.10","5.1.6","5.2.12","5.3.5","5.3.4","5.3.3","5.3.2","5.2.11","5.3.1","5.3.0","4.6.3","5.2.10","5.2.9","5.2.8","4.6.2","5.2.7","5.2.6","5.2.5","4.6.1","5.2.4","5.2.3","5.2.2","5.2.1","5.2.0","4.6.0","4.5.9","5.1.5","5.1.4","4.5.8","5.1.2","4.5.7","5.1.1","5.1.0","5.0.11","4.5.6","5.0.10","5.0.9","4.5.5","5.0.8","5.0.7","5.0.6","4.5.4","5.0.5","4.5.3","5.0.4","4.5.2","5.0.3","4.5.1","5.0.2","4.5.0","5.0.1","4.4.18","5.0.0","4.4.17","4.4.15","4.4.16","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.4.0","4.4.0-RC2","4.4.0-RC1","4.3.0-RC4","4.3.0-RC3","4.3.0-RC2","4.3.0-RC1","4.0.0","4.2.0-RC1","4.2.0-beta1","4.1.0-RC2","4.1.0-RC1","4.1.0-beta1","4.0.0-RC2","4.0.0-RC1","4.0.0-beta4","4.0.0-beta3","4.0.0-beta2","4.0.0-beta1","4.0.0-alpha2","4.0.0-alpha1","3.5.15","3.6.0","3.5.14","3.5.13","3.5.12","3.5.11","3.5.10","3.5.9","3.5.8","3.5.7","3.5.6","3.5.5","3.5.4","3.5.3","3.5.2","3.5.1","3.5.0","3.5.0-RC2","3.5.0-RC1","3.4.0-RC4","3.4.0-RC3","3.4.0-RC2","3.4.0-RC1","3.4.0-beta4","3.4.0-beta3","3.4.0-beta2","3.4.0-beta1","3.3.0-RC1","3.3.0-beta3","3.3.0-beta2","3.3.0-beta","3.1.9","3.2.0","3.1.8","3.1.7","3.1.6","3.1.4","3.1.5","3.1.3","3.1.2","3.1.1","3.1.0","3.0.13","3.0.12","3.0.11","3.0.10","3.0.9","3.0.8","3.0.7","3.0.6","3.0.5","3.0.4","3.0.3","3.0.2","3.0.1","3.0.0","3.0.0-RC2","3.0.0-RC1","3.0.0-beta3","3.0.0-beta2","3.0.0-beta1","3.0.0-alpha2","3.0.0-alpha1","3.0.0-dev3","3.0.0-dev2","3.0.0-dev1","2.2.0-RC1","2.2.0-beta","2.1.0","2.1.0-RC","2.1.0-beta","2.1.0-alpha","2.0.0-RC1","2.0.0-beta","2.0.0-alpha","2.0.0-dev","1.3.0-RC2","1.3.0-RC1","1.3.0-beta","1.3.0-alpha","1.3-dev","1.2.1","1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79752.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}