PT-2025-32419 · Craft · Craft

Segfault-It

·

Published

2025-08-08

·

Updated

2025-08-09

·

CVE-2025-54417

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft versions 4.13.8 through 4.16.2 Craft versions 5.5.8 through 5.8.3
Description Craft is a platform for creating digital experiences. A vulnerability exists that allows bypassing security measures, potentially leading to remote code execution (RCE) with a compromised security key. To exploit this issue, an attacker must have a compromised security key and the ability to create an arbitrary file in Craft's /storage/backups folder. Exploitation involves sending a malicious request to the /updater/restore-db endpoint, enabling the execution of CLI commands remotely.
Recommendations Craft versions prior to 4.16.3 Craft versions prior to 5.8.4

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54417
GHSA-2VCF-QXV3-2MGW

Affected Products

Craft