Craft CMS has a theoretical bypass for CVE-2025-23209
Package
Affected versions
>= 4.13.8, < 4.16.3
>= 5.5.8, < 5.8.4
Patched versions
4.16.3
5.8.4
Description
Published to the GitHub Advisory Database
Aug 8, 2025
Reviewed
Aug 8, 2025
Published by the National Vulnerability Database
Aug 9, 2025
Last updated
Aug 11, 2025
Pre-requisites:
/storage/backups
folder.With those two pieces in place, you could create a specific, malicious request to the
/updater/restore-db
endpoint to execute CLI commands remotely.Fixed in craftcms/cms@a19d46b
Reported by Marco O. (segfault)
References