CVE-2026-55590Medium▾ SunlitCakePHP Authentication: Open redirect weakness via backslash bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.6%
The getLoginRedirect() method contains a weakness to backslash bypasses allowing redirect targets with attacker controlled hostnames.
3.3.6 and 4.1.1 contain a fix for this issue.
If you are unable to upgrade, you should consider adding application validation to the redirect query string parameter to mitigate this vulnerability.
cakephp/authentication < 3.3.6cakephp/authentication >= 4.0.0, < 4.1.1Upgrade to a patched release:
cakephp/authentication 3.3.6cakephp/authentication 4.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79752Critical· 9.2CakePHP is a rapid development framework for PHP
CVE-2026-77635CriticalCakePHP is a rapid development framework for PHP
CVE-2026-77634HighCakePHP is a rapid development framework for PHP
CVE-2026-54713Low· 3.7CakePHP Queue is a queue-interop compatible queueing library
CVE-2026-54614Medium· 4.3DebugKit provides a debugging toolbar for CakePHP applications
CVE-2024-0953Medium· 6.1When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code