PT-2025-17927 · Craft · Craft
Nicolas Bourras
+2
·
Published
2025-04-25
·
Updated
2026-01-12
·
CVE-2025-32432
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Craft versions 3.0.0-RC1 through 3.9.14
Craft versions 4.0.0-RC1 through 4.14.14
Craft versions 5.0.0-RC1 through 5.6.16
Description
Craft CMS is vulnerable to remote code execution. This is a high-impact, low-complexity issue. The Mimo intrusion set has been observed exploiting this vulnerability to deploy webshells, loaders, and proxyware, including the XMRig cryptominer and IPRoyal proxy service. Attackers are utilizing techniques to conceal malicious activity, indicating a focus on financial gain and potential expansion into ransomware. Approximately 13,000 instances are vulnerable, with around 300 already compromised. The vulnerability is related to improper handling of code generation. The exploitation involves sending a specially crafted GET request to deploy a webshell, enabling the execution of arbitrary commands on the compromised server. The attackers employ methods to evade detection, such as using the
alamdar.so library to hide malicious processes.Recommendations
Update Craft CMS to version 3.9.15 or later.
Update Craft CMS to version 4.14.15 or later.
Update Craft CMS to version 5.6.17 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-06516
CVE-2025-32432
GHSA-F3GW-9WW9-JMC3
Affected Products
Craft
References · 153
- 🔥 https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms · Exploit
- https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47⭐ 3488 🔗 680 · Patch
- https://osv.dev/vulnerability/GHSA-f3gw-9ww9-jmc3 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-06516 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-32432 · Security Note
- https://osv.dev/vulnerability/CVE-2025-32432 · Vendor Advisory
- https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical⭐ 3488 🔗 680 · Note
- https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical⭐ 3488 🔗 680 · Note
- https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical⭐ 3488 🔗 680 · Note
- https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3⭐ 3488 🔗 680 · Note
- https://github.com/craftcms/cms⭐ 3468 🔗 678 · Note
- https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g⭐ 3410 🔗 669 · Note
- https://twitter.com/TweetThreatNews/status/1927419685479334055 · Twitter Post
- https://twitter.com/Dinosn/status/1927730714755158371 · Twitter Post
- https://twitter.com/transilienceai/status/1921536920611373121 · Twitter Post