Feed/CVE-2026-48820
CVE-2026-48820MEDIUMCVSS 0.0

CakePHP: View::element() is missing a path containment check

Published Jun 26, 2026·Updated Jun 26, 2026

NVD Description

### Impact `View::_getElementFileName()` does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. ### Patches Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11. ### Workarounds If developers are not using user-supplied data in element names, no action is required.

Affected Packages (1)

cakephp/cakephpCOMPOSER
From 5.3.0
Fixed in 5.3.6

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free