CVE-2025-54417
EPSS 0.08%Craft CMS has a theoretical bypass for CVE-2025-23209
Published: 8/8/2025Modified: 8/11/2025
Also known as:GHSA-2vcf-qxv3-2mgw
Description
**Pre-requisites:** * Have a compromised security key (https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret) * Somehow, manage to create an arbitrary file in Craft’s `/storage/backups` folder. With those two pieces in place, you could create a specific, malicious request to the `/updater/restore-db` endpoint to execute CLI commands remotely. Fixed in https://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57 ----- Reported by Marco O. (segfault)
Affected packages (1)
- Packagist/craftcms/cms>= 4.13.8, < 4.16.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-23209
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-54417
- PATCHhttps://github.com/craftcms/cms
- WEBhttps://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57
- WEBhttps://github.com/craftcms/cms/security/advisories/GHSA-2vcf-qxv3-2mgw