Skip to content

Potential bypass for CVE-2025-23209

Low
angrybrad published GHSA-2vcf-qxv3-2mgw Aug 8, 2025

Package

composer craftcms/cms (Composer)

Affected versions

>= 4.13.8, < 4.16.3
>= 5.5.8, < 5.8.4

Patched versions

4.16.3
5.8.4

Description

Pre-requisites:

With those two pieces in place, you could create a specific, malicious request to the /updater/restore-db endpoint to execute CLI commands remotely.

Fixed in a19d46b


Reported by Marco O. (segfault)

Severity

Low

CVE ID

CVE-2025-54417

Weaknesses

No CWEs

Credits