Threat Advisory

Phalcon Vulnerability Hijacks Volt Join Filter for Malicious Routines

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-59989, with a CVSS score of 9.2, is a vulnerability affecting Phalcon in the Phalcon Volt compiler that allows arbitrary code injection through server-side template injection, leading to remote code execution in the web-server process. The issue arises when the join filter's raw template-literal argument bytes are string-concatenated without escaping, allowing attackers to inject arbitrary PHP code into the compiled template, which is then written to a cache file and executed at render time. This vulnerability affects applications that compile Volt source that is wholly or partly attacker-controlled, enabling attackers to execute arbitrary code within the web-server process. The flaw type is server-side template injection (SSTI), with a local network attack vector, and its business impact is significant because successful exploitation can result in arbitrary command execution on the affected web server.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

CVE-2026-59989, with a CVSS score of 9.2, is a vulnerability affecting Phalcon in the Phalcon Volt compiler that allows arbitrary code injection through server-side template injection, leading to remote code execution in the web-server process. The issue arises when the join filter's raw template-literal argument bytes are string-concatenated without escaping, allowing attackers to inject arbitrary PHP code into the compiled template, which is then written to a cache file and executed at render time. This vulnerability affects applications that compile Volt source that is wholly or partly attacker-controlled, enabling attackers to execute arbitrary code within the web-server process. The flaw type is server-side template injection (SSTI), with a local network attack vector, and its business impact is significant because successful exploitation can result in arbitrary command execution on the affected web server.[emaillocker id="1283"]

 

RECOMMENDATIONS:

  • We recommend you to update phalcon/cphalcon to version 5.20.0 or later.

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-hrwp-4hh9-c8r8

[/emaillocker]
crossmenu