๐Ÿ” CVE Alert

CVE-2026-54614

MEDIUM 4.3

DebugKit: MailPreview contains unsafe reflection

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes the resolved class from App::className() to constructor execution without rejecting namespace separators or verifying that the class extends DebugKit\Mailer\MailPreview. An attacker able to access DebugKit while debug mode is enabled and the request hostname is local or allowlisted can select an unintended application class through the mail-preview preview route, resulting in arbitrary constructor execution and limited disclosure of application information. This issue is fixed in versions 4.10.3 and 5.2.4.

CWE CWE-470
Vendor cakephp
Product debug_kit
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for cakephp debug_kit

Be the first to know when new medium vulnerabilities affecting cakephp debug_kit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

cakephp / debug_kit
< 4.10.3 >= 5.0.0, < 5.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cakephp/debug_kit/security/advisories/GHSA-p46m-g734-vpc4 github.com: https://github.com/cakephp/debug_kit/pull/1078 github.com: https://github.com/cakephp/debug_kit/commit/7c4d85e984c2334b0f50cd02578a927ff9649e13 github.com: https://github.com/cakephp/debug_kit/commit/c8a2a9e07d56a5e212d95f6947f370f3b5e6eed6 github.com: https://github.com/cakephp/debug_kit/releases/tag/4.10.3 github.com: https://github.com/cakephp/debug_kit/releases/tag/5.2.4