Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-39552 is a PHP Local File Inclusion (LFI) vulnerability in Code Supply Co.'s Blueprint, affecting versions before 1.1.5. This CWE-98 weakness—improper control of filenames in include/require statements—allows attackers to manipulate file paths and access arbitrary local files on the server. Organizations using Blueprint for code management or deployment automation are at risk, particularly in environments where user input influences file inclusion operations. An attacker exploiting this vulnerability could read sensitive files like configuration files containing credentials, source code, or system information, potentially leading to further compromise of the application or infrastructure.
While this CVE lacks explicit MITRE ATT&CK mapping, Casky.ai's 754 mapped security skills would detect the attack patterns associated with this vulnerability through reconnaissance and credential access techniques. Practitioners analyzing Blueprint deployments would observe security findings related to improper input validation, unsanitized file path parameters, and suspicious file access patterns—particularly attempts to include files outside intended directories using path traversal sequences (../, ..\, or encoded variants). Extended reasoning through Claude AI would correlate these indicators with CWE-98 patterns, helping security teams identify both vulnerable code patterns during development and exploitation attempts in runtime logs, enabling rapid patching and threat hunting before attackers escalate from file disclosure to system compromise.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-39552. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation