Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106512— MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS

Quick assessment

Affected
MISP sachertortephp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

文件中的 方法在构建 响应头时,直接将用户提供的文件名插入了双引号字符串中,且未进行任何 sanitization(清理/转义)处理。未修复的代码中存在两种不同的注入向量: 1. C0 控制字符注入:如果文件名包含 C0 控制字符(回车符 CR 或换行符 LF),PHP 将无法发送整个 头,从而静默丢弃附件处置指令。此时,响应体会以自身的 (例如,HTML 附件对应的 )被提供,并在浏览器中原生页面上下文中以内联方式渲染,从而导致存储型跨站脚本(Stored XSS)漏洞。提交记录指出,即使启用了 设置,此漏洞仍可

CVSS 8.4 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
MISP sachertortephp ≤ 1c2da20cbe3f1e2a91458fe9a017823b7273fdac affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106512

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS
Source: CVE Program / CVE List V5
Vulnerability Description
The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
HTTP头部中CRLF序列转义处理不恰当(HTTP响应分割)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MISP sachertortephp 0 ~ 1c2da20cbe3f1e2a91458fe9a017823b7273fdac cpe:2.3:a:misp:sachertortephp_\(cakephp-based_misp_application\):*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-106512

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106512

请登录查看更多情报信息。

Other References for CVE-2026-106512 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106512

No comments yet


Leave a comment