漏洞情报聚合

CVE-2026-59989 - Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP without passing them through expression(). An attacker who can influence Volt template source can place quote-breaking content in a join argument, inject PHP into the compiled cache file, and execute it when Phalcon\Mvc\View\Engine\Volt::render() l - 漏洞详情

漏洞编号:CVE-2026-59989

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-59989

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-94

发布/更新时间:2026-08-21 / 2026-08-27

漏洞描述

Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP without passing them through expression(). An attacker who can influence Volt template source can place quote-breaking content in a join argument, inject PHP into the compiled cache file, and execute it when Phalcon\Mvc\View\Engine\Volt::render() loads the template. This issue is fixed in version 5.16.0.

相关链接

相关漏洞

« 返回首页