CVE-2026-59989 | Phalcon up to 5.15.0 Volt Compiler.zep resolveFilter join code injection

SecurityVulns

A vulnerability identified as critical has been detected in Phalcon up to 5.15.0. Affected by this vulnerability is the function PhalconMvcViewEngineVoltCompiler::resolveFilter of the file phalcon/Mvc/View/Engine/Volt/Compiler.zep of the component Volt. This manipulation of the argument join causes code injection.

This vulnerability is tracked as CVE-2026-59989. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.VulDB Recent EntriesRead More