{"api_version":"1","generated_at":"2026-10-06T22:10:23+00:00","cve":"CVE-2026-106512","urls":{"html":"https://cve.report/CVE-2026-106512","api":"https://cve.report/api/cve/CVE-2026-106512.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-106512","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-106512"},"summary":{"title":"MISP sachertortephp  - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS","description":"The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.","state":"PUBLISHED","assigner":"CIRCL","published_at":"2026-10-06 19:18:13","updated_at":"2026-10-06 20:06:12"},"problem_types":["CWE-20","CWE-79","CWE-113","CWE-113 CWE-113 HTTP Response Splitting","CWE-79 CWE-79 Cross-site Scripting (XSS)","CWE-20 CWE-20 Improper Input Validation"],"metrics":[{"version":"4.0","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","score":"8.4","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.4","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.4,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd","name":"https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439","name":"https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439","refsource":"5a6e4751-2f3f-4070-9419-94fb35b644e8","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-106512","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106512","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MISP","product":"sachertortephp","version":"affected 1c2da20cbe3f1e2a91458fe9a017823b7273fdac semver","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The vulnerability is remediated by sanitizing the filename before it is interpolated into the Content-Disposition header. C0 control characters (0x00-0x1F) and DEL (0x7F) are stripped to prevent HTTP response splitting and header suppression. Subsequently, double-quote and backslash characters are escaped using addcslashes per RFC 6266 quoted-string rules to prevent early termination of the quoted value and injection of additional header parameters. Together these two steps ensure the filename remains contained within the intended quoted-string token regardless of its content.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Logan Homolka","lang":"en"},{"source":"CNA","value":"iglocska","lang":"en"},{"source":"CNA","value":"Claude Opus 4.8","lang":"en"},{"source":"CNA","value":"Claude Opus 4.8","lang":"en"},{"source":"CNA","value":"CCB","lang":"en"},{"source":"CNA","value":"Alexandre Dulaunoy","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:misp:sachertortephp_\\(cakephp-based_misp_application\\):*:*:*:*:*:*:*:*"],"modules":["CakeResponse::download()"],"product":"sachertortephp","programFiles":["lib/Cake/Network/CakeResponse.php"],"repo":"https://github.com/MISP/sachertortephp","vendor":"MISP","versions":[{"lessThanOrEqual":"1c2da20cbe3f1e2a91458fe9a017823b7273fdac","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Logan Homolka"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"},{"lang":"en","type":"tool","value":"Claude Opus 4.8"},{"lang":"en","type":"coordinator","value":"CCB"},{"lang":"en","type":"coordinator","value":"Alexandre Dulaunoy"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.</p>"}],"value":"The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim."}],"impacts":[{"capecId":"CAPEC-66","descriptions":[{"lang":"en","value":"CAPEC-66 HTTP Request/Response Splitting"}]},{"capecId":"CAPEC-2","descriptions":[{"lang":"en","value":"CAPEC-2 Input with Special Elements or Structures"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.4,"baseSeverity":"HIGH","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"format":"SSVC","other":{"content":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-06T18:44:54Z","version":"2.0.3"},"type":"SSVC"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-113","description":"CWE-113 HTTP Response Splitting","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting (XSS)","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T18:48:29.598Z","orgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","shortName":"CIRCL"},"references":[{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd"},{"name":"Security patch","tags":["patch"],"url":"https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability is remediated by sanitizing the filename before it is interpolated into the Content-Disposition header. C0 control characters (0x00-0x1F) and DEL (0x7F) are stripped to prevent HTTP response splitting and header suppression. Subsequently, double-quote and backslash characters are escaped using addcslashes per RFC 6266 quoted-string rules to prevent early termination of the quoted value and injection of additional header parameters. Together these two steps ensure the filename remains contained within the intended quoted-string token regardless of its content.</p>"}],"value":"The vulnerability is remediated by sanitizing the filename before it is interpolated into the Content-Disposition header. C0 control characters (0x00-0x1F) and DEL (0x7F) are stripped to prevent HTTP response splitting and header suppression. Subsequently, double-quote and backslash characters are escaped using addcslashes per RFC 6266 quoted-string rules to prevent early termination of the quoted value and injection of additional header parameters. Together these two steps ensure the filename remains contained within the intended quoted-string token regardless of its content."}],"title":"MISP sachertortephp  - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS","x_gcve":[{"extensions":{"bcp-05-x-01":{"ai_annotations":[{"ai_level":"generated","description":"Draft vulnerability metadata was generated from a git-format patch using an Ollama-hosted language model. Human validation is required before publication.","gna_source":1,"models":[{"gna_source":1,"identifier":"qwen3.8:27b","name":"qwen3.8:27b","source":"ollama"}],"review_status":"partial","scope":"record","tags":["ai-computer-assisted:llm-generated","ai-computer-assisted:classification"]}]},"bcp-05-x-02":{"x_patch2vuln":{"assumptions":["The affected product is identified as MISP sachertortephp based on the GitHub repository URL in the patch metadata; no specific version range is provided in the patch or metadata.","PR:L assumes that creating or uploading an attachment with a crafted filename requires authenticated access to the MISP instance; the patch does not explicitly state the authentication model.","UI:N assumes the victim triggers the download by normal page navigation; the commit message states the issue is reachable with download_attachments_on_load enabled, implying no special user action beyond viewing the page.","SC:H assumes the rendered HTML/JavaScript on the application origin grants full access to the victim's session and data, consistent with standard stored XSS impact.","The CAPEC-66 mapping is the closest available pattern for HTTP response header manipulation via CRLF injection; CAPEC-2 is included as a supplementary general-purpose pattern. Neither CAPEC perfectly captures the combined CRLF-suppression and quote-injection mechanism.","The Co-Authored-By line referencing Claude Opus 4.8 is treated as a tool credit per the metadata remediation_developers field; it is not a human contributor.","The patch does not specify whether the filename is attacker-controlled at creation time or only at serve time; the commit message states it 'neutralises already-stored filenames on serve,' implying the filename may have been stored before the fix."],"capecRationale":[{"capecId":"CAPEC-66","rationale":"The attacker injects CRLF sequences into the filename field, which is reflected into the Content-Disposition HTTP response header. This causes the header to be suppressed or its structure altered, matching the HTTP response splitting attack pattern. The quote-injection variant is a secondary header parameter injection that also falls under this pattern."},{"capecId":"CAPEC-2","rationale":"The attack relies on supplying special characters (CRLF, double-quote) in a user-controlled input field (the attachment filename) that the application fails to neutralize before using it in a structured output context (HTTP header). This is the closest general-purpose CAPEC for injection via special characters when a more specific pattern is not available."}],"commit":"e2c80021729611922817a57d2317b2ffa7ed1439","confidence":"medium","credits":[{"lang":"en","type":"reporter","value":"Logan Homolka"},{"lang":"en","type":"remediation developer","value":"iglocska"},{"lang":"en","type":"remediation developer","value":"Claude Opus 4.8"},{"lang":"en","type":"tool","value":"Claude Opus 4.8"}],"cvssRationale":"AV:N: The vulnerability is exploitable over the network via HTTP. AC:L: No race conditions or special timing are required; a crafted filename is sufficient. AT:N: The malicious filename is stored in the application; no manipulation of the attack target is needed at exploit time. PR:L: An authenticated MISP user with the ability to create or upload an attachment is required to store the crafted filename. UI:N: The victim only needs to view a page that triggers the download; no specific interaction beyond normal browsing is required. VC/VI/VA:N: The vulnerable component (the MISP server) itself is not directly compromised in terms of its own confidentiality, integrity, or availability. SC:H: The rendered HTML/JavaScript executes in the victim's browser on the application origin, granting full access to the victim's session, cookies, and data. SI:L: The attacker can modify what the victim sees and potentially submit forms on the victim's behalf. SA:N: No availability impact on the victim's system.","fixSummary":"The vulnerability is remediated by sanitizing the filename before it is interpolated into the Content-Disposition header. C0 control characters (0x00-0x1F) and DEL (0x7F) are stripped to prevent HTTP response splitting and header suppression. Subsequently, double-quote and backslash characters are escaped using addcslashes per RFC 6266 quoted-string rules to prevent early termination of the quoted value and injection of additional header parameters. Together these two steps ensure the filename remains contained within the intended quoted-string token regardless of its content.","generatedAt":"2026-10-06T18:44:54.540983Z","generator":"patch2vuln.py","model":"qwen3.8:27b","modelComparison":{"rankings":[{"agreementScore":11,"assumptionCount":7,"confidence":"medium","model":"qwen3.8:27b","score":5}],"selectedModel":"qwen3.8:27b","selectionMethod":"deterministic-consensus-v1","selectionNotice":"The selected result is closest to model consensus; this heuristic does not establish factual correctness and human review remains required."},"patchSha256":"ce7901c623bbc59c2f5f8dfe8ce0bd4445c8bb6c1865356f21812d80509db854","patchSummary":"Two commits modify CakeResponse::download() in lib/Cake/Network/CakeResponse.php. The first commit (afbc551) adds a preg_replace call that strips all C0 control characters and DEL from the filename string before the header is composed. The second commit (e2c8002) adds an addcslashes call that escapes double-quote and backslash characters in the filename after the control-character strip, ensuring the quoted-string value in the Content-Disposition header cannot be broken out of. Both changes are inserted immediately before the existing $this->header('Content-Disposition', ...) call.","patchTruncated":false,"patches":[{"commit":"afbc551aa6b8aedb87dfa1223a388e9a3178abfd","date":"Tue, 6 Oct 2026 19:27:40 +0200","patchSha256":"9430abddfb8d3a9f5f642b6b2700aa00186c9f11966591e408e39f20a1e4ccdc","source":"https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd.patch","sourceUrl":"https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd.patch","subject":"fix: [security] Strip control characters from download"},{"commit":"e2c80021729611922817a57d2317b2ffa7ed1439","date":"Tue, 6 Oct 2026 20:20:13 +0200","patchSha256":"41c2630e0a4b0a1a3d4612c28531f4f673164fbee41dcc2b3a43813640fd0e39","source":"https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439.patch","sourceUrl":"https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439.patch","subject":"fix: [security] Escape the download filename quoted-string"}],"source":"patch set (2 sources)","ssvc":{"options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"Supplier","timestamp":"2026-10-06T18:44:54Z","version":"2.0.3"},"subject":"fix: [security] Escape the download filename quoted-string","weaknessRationale":[{"cweId":"CWE-113","rationale":"CRLF characters in the unsanitized filename cause PHP to suppress the entire Content-Disposition header, effectively splitting or altering the HTTP response structure. This is the primary mechanism by which the attachment disposition is dropped and the body renders inline."},{"cweId":"CWE-79","rationale":"The consequence of the header suppression is that an HTML attachment renders inline on the application origin, constituting a stored XSS condition. The quote-injection variant (CWE-74) also contributes to the header manipulation but the security impact is best characterized as XSS."},{"cweId":"CWE-20","rationale":"The root cause is the absence of input validation and output encoding on the filename parameter before it is placed into an HTTP header value. Both the control-character and quote-injection variants stem from this missing validation."}]}},"bcp-05-x-03":{"x_timeline":{"events":[{"description":"Corrective change authored (afbc551aa6b8aedb87dfa1223a388e9a3178abfd): fix: [security] Strip control characters from download","id":"evt-fix-developed-1","references":["https://github.com/MISP/sachertortephp/commit/afbc551aa6b8aedb87dfa1223a388e9a3178abfd.patch"],"timestamp":"2026-10-06T17:27:40Z","type":"fix-developed"},{"description":"Corrective change authored (e2c80021729611922817a57d2317b2ffa7ed1439): fix: [security] Escape the download filename quoted-string","id":"evt-fix-developed-2","references":["https://github.com/MISP/sachertortephp/commit/e2c80021729611922817a57d2317b2ffa7ed1439.patch"],"timestamp":"2026-10-06T18:20:13Z","type":"fix-developed"}]}}},"recordType":"advisory","vulnId":"gcve-1-2026-20275"}]}},"cveMetadata":{"assignerOrgId":"5a6e4751-2f3f-4070-9419-94fb35b644e8","assignerShortName":"CIRCL","cveId":"CVE-2026-106512","datePublished":"2026-10-06T18:48:29.598Z","dateReserved":"2026-10-06T18:48:26.050Z","dateUpdated":"2026-10-06T18:48:29.598Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 19:18:13","lastModifiedDate":"2026-10-06 20:06:12","problem_types":["CWE-20","CWE-79","CWE-113","CWE-113 CWE-113 HTTP Response Splitting","CWE-79 CWE-79 Cross-site Scripting (XSS)","CWE-20 CWE-20 Improper Input Validation"],"metrics":{"cvssMetricV40":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","ssvcData":{"timestamp":"2026-10-06T18:44:54Z","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"Supplier","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"106512","Ordinal":"1","Title":"MISP sachertortephp  - CakeResponse::download() HTTP Response Sp","CVE":"CVE-2026-106512","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"106512","Ordinal":"1","NoteData":"The CakeResponse::download() method in lib/Cake/Network/CakeResponse.php constructs a Content-Disposition header by directly interpolating a caller-supplied filename into a quoted-string value without sanitization. Two distinct injection vectors exist in the unpatched code. First, if the filename contains C0 control characters (CR or LF), PHP refuses to emit the entire Content-Disposition header, silently dropping the attachment disposition. The response body is then served with its own Content-Type (for example text/html for an .html attachment) and renders inline in the browser on the application origin, creating a stored cross-site scripting condition. The commit message notes this is reachable even when the download_attachments_on_load setting is enabled, meaning a victim merely needs to view a page that triggers the download. Second, a double-quote character in the filename terminates the quoted-string value early, permitting injection of additional Content-Disposition parameters. The affected code path covers all callers of CakeResponse::download(), including attribute downloads, proposal downloads, and restSearch exports. An authenticated user who can create or upload an attachment with a crafted filename (for example through MISP attribute naming or proposal attachment naming) can store the malicious filename. When any other authenticated user views the affected page, the unsanitized filename is reflected into the HTTP response header, resulting in header manipulation and potential execution of arbitrary HTML or JavaScript in the context of the application origin. The security impact is equivalent to a stored cross-site scripting vulnerability, allowing session hijacking, data exfiltration, and unauthorized actions on behalf of the victim.","Type":"Description","Title":"MISP sachertortephp  - CakeResponse::download() HTTP Response Sp"}]}}}