PT-2025-32419 · Craft · Craft
Segfault-It
·
Published
2025-08-08
·
Updated
2025-08-09
·
CVE-2025-54417
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Craft versions 4.13.8 through 4.16.2
Craft versions 5.5.8 through 5.8.3
Description
Craft is a platform for creating digital experiences. A vulnerability exists that allows bypassing security measures, potentially leading to remote code execution (RCE) with a compromised security key. To exploit this issue, an attacker must have a compromised security key and the ability to create an arbitrary file in Craft's
/storage/backups folder. Exploitation involves sending a malicious request to the /updater/restore-db endpoint, enabling the execution of CLI commands remotely.Recommendations
Craft versions prior to 4.16.3
Craft versions prior to 5.8.4
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft