Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
Package
Affected versions
>= 4.0.0-RC1, <= 4.14.12
>= 5.0.0-RC1, <= 5.6.14
Patched versions
4.14.13
5.6.15
Description
Published to the GitHub Advisory Database
May 5, 2025
Reviewed
May 5, 2025
Published by the National Vulnerability Database
May 5, 2025
Last updated
May 5, 2025
Craft CMS contains a potential remote code execution vulnerability via Twig SSTI. You must have administrator access and
ALLOW_ADMIN_CHANGES
must be enabled for this to work.https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production
Note: This is a follow-up to GHSA-f3cw-hg6r-chfv
Users should update to the patched versions (4.14.13 and 5.6.15) to mitigate the issue.
References
craftcms/cms#17026
References