EXECUTIVE SUMMARY:
CVE-2026-59989, with a CVSS score of 9.2, is a vulnerability affecting Phalcon in the Phalcon Volt compiler that allows arbitrary code injection through server-side template injection, leading to remote code execution in the web-server process. The issue arises when the join filter's raw template-literal argument bytes are string-concatenated without escaping, allowing attackers to inject arbitrary PHP code into the compiled template, which is then written to a cache file and executed at render time. This vulnerability affects applications that compile Volt source that is wholly or partly attacker-controlled, enabling attackers to execute arbitrary code within the web-server process. The flaw type is server-side template injection (SSTI), with a local network attack vector, and its business impact is significant because successful exploitation can result in arbitrary command execution on the affected web server.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2026-59989, with a CVSS score of 9.2, is a vulnerability affecting Phalcon in the Phalcon Volt compiler that allows arbitrary code injection through server-side template injection, leading to remote code execution in the web-server process. The issue arises when the join filter's raw template-literal argument bytes are string-concatenated without escaping, allowing attackers to inject arbitrary PHP code into the compiled template, which is then written to a cache file and executed at render time. This vulnerability affects applications that compile Volt source that is wholly or partly attacker-controlled, enabling attackers to execute arbitrary code within the web-server process. The flaw type is server-side template injection (SSTI), with a local network attack vector, and its business impact is significant because successful exploitation can result in arbitrary command execution on the affected web server.[emaillocker id="1283"]
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-hrwp-4hh9-c8r8