Code Injection Vulnerability in CakePHP Product by MISP
CVE-2026-106512
What is CVE-2026-106512?
The CakeResponse::download() method in CakePHP allows for security vulnerabilities due to improper handling of user-supplied filenames in the Content-Disposition header. Attackers can exploit this by embedding C0 control characters or double quotes in filenames, leading to potential stored cross-site scripting (XSS) vulnerabilities. If an affected file is triggered for download, it could let malicious scripts execute in the context of a user's session, leading to session hijacking, unauthorized data access, and more. The vulnerability affects all implementations of CakeResponse::download(), impacting various functionalities such as file attachments and exports.
Affected Version(s)
sachertortephp 0 <= 1c2da20cbe3f1e2a91458fe9a017823b7273fdac
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
