PHP Framework Vulnerability in Phalcon 5.15.0 and Earlier
CVE-2026-59989
9.2CRITICAL
What is CVE-2026-59989?
In the Phalcon framework, a vulnerability exists in the resolveFilter method of the Volt compiler, where raw separator and array token values are directly inserted into generated PHP code without proper sanitization. This flaw allows attackers with influence over Volt templates to craft malicious input that can break quotes, leading to arbitrary PHP code execution in the compiled cache once the template is rendered. The issue has been addressed in version 5.16.0, and users of affected versions are advised to update promptly to mitigate risks.
Affected Version(s)
cphalcon < 5.16.0
