CVE-2026-106512 Details
Description
The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.
A vulnerability exists in the CakeResponse::download() method of MISP's sachertortephp library, specifically in versions prior to the recent patch. The issue arises because the method constructs a Content-Disposition header by directly inserting user-supplied filenames into a quoted-string format without proper sanitization. This flaw creates two distinct injection vectors. Firstly, if a filename includes C0 control characters such as carriage return or line feed, PHP will omit the entire Content-Disposition header. As a result, the response body is served with its default Content-Type—such as text/html for .html files—causing the content to render inline in the browser instead of prompting a download. This behavior creates a stored cross-site scripting vulnerability, as the injected script can be executed when the page is viewed. Secondly, if a filename contains a double-quote, it can prematurely terminate the quoted-string value, allowing the injection of additional Content-Disposition parameters. The vulnerability affects all instances where CakeResponse::download() is called, including attribute and proposal downloads, as well as restSearch exports. An authenticated user who can upload or create attachments with manipulated filenames can exploit this issue. Once the malicious filename is stored, any other authenticated user who accesses the relevant page will trigger the execution of the injected content, potentially leading to session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.
The vulnerability has been patched by stripping control characters and double quotes from filenames in the CakeResponse::download() method before the header is composed. This update is included in the latest version of the sachertortephp library.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 6, 2026CISA-ADP
Assessed Oct 7, 2026Supplier
Assessed Oct 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd | CIRCL | Source CodeVendor |
| https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439 | CIRCL | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | CIRCL |
| CWE-20 | Improper Input Validation | CIRCL |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CIRCL |
Affected Products
| Product | Versions |
|---|---|
| CakePHP | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 7, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2026 | New CVE Received | CIRCL |
Volerion