PT-2025-15893 · Yii · Yii

Published

2024-07-25

·

Updated

2025-11-05

·

CVE-2024-58136

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yii 2 versions prior to 2.0.52
Description The issue arises from the mishandling of behavior attachment, specifically when behaviors are defined by a class array key. This has been exploited in the wild, with approximately 13,000 vulnerable instances and around 300 already compromised. Attackers are chaining flaws to breach servers and deploy malicious scripts. The vulnerability has been actively exploited since at least February 2025.
Recommendations For versions prior to 2.0.52, patch immediately to a version that contains the fix for this issue. As a temporary workaround, consider disabling the attachment of behaviors defined by a class array key until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the class array key in behavior definitions until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-06103
CVE-2024-58136
GHSA-GGWG-CMWP-46R5

Affected Products

Yii