Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. cakephp/cakephp
  4. ›
  5. CVE-2026-48820

CVE-2026-48820: CakePHP: View::element() is missing a path containment check

June 26, 2026

View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server.

References

  • github.com/advisories/GHSA-wpvj-hjcr-h3p2
  • github.com/cakephp/cakephp/security/advisories/GHSA-wpvj-hjcr-h3p2
  • nvd.nist.gov/vuln/detail/CVE-2026-48820

Code Behaviors & Features

Detect and mitigate CVE-2026-48820 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.5.11, all versions starting from 4.6.0 before 4.6.4, all versions starting from 5.0.0 before 5.1.7, all versions starting from 5.2.0 before 5.2.13, all versions starting from 5.3.0 before 5.3.6

Fixed versions

  • 4.5.11
  • 4.6.4
  • 5.1.7
  • 5.2.13
  • 5.3.6

Solution

Upgrade to versions 4.5.11, 4.6.4, 5.1.7, 5.2.13, 5.3.6 or above.

Impact 3.7 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

packagist/cakephp/cakephp/CVE-2026-48820.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 00:17:41 +0000.