cakephp/cakephp
CriticalComposerCVE-2026-77635
What to do
Update cakephp/cakephp to 5.3.7 or later.
composer require cakephp/cakephp:^5.3.7
An injection flaw affects the Composer package cakephp/cakephp. Affected versions: >= 5.3.0, < 5.3.7. Fixed from version 5.3.7.
What the flaw allows: User-supplied data is interpreted as instructions.
- Package
- cakephp/cakephp
- Ecosystem
- Composer (PHP)
- Class
- Injection
- Affected versions
- >= 5.3.0, < 5.3.7
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.