logo

CVE-2025-57811 craftcms/cms

Package

Manager: composer
Name: craftcms/cms
Vulnerable Version: >=4.0.0-rc1 <4.16.6 || >=5.0.0-rc1 <5.8.7

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:H/RL:U/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

EPSS: 0.00358 pctl0.5727

Details

Craft CMS Potential Remote Code Execution via Twig SSTI You must have administrator access, and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production Note: This is a follow-up to [GHSA-f3cw-hg6r-chfv](https://github.com/craftcms/cms/security/advisories/GHSA-f3cw-hg6r-chfv) Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue. References: https://github.com/craftcms/cms/pull/17612

Metadata

Created: 2025-08-25T20:42:45Z
Modified: 2025-08-26T17:12:20Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-crcq-738g-pqvc/GHSA-crcq-738g-pqvc.json
CWE IDs: ["CWE-1336", "CWE-22", "CWE-94"]
Alternative ID: GHSA-crcq-738g-pqvc
Finding: F422
Auto approve: 1