Craft CMS Allows Remote Code Execution
Package
Affected versions
>= 3.0.0-RC1, <= 3.9.14
>= 4.0.0-RC1, <= 4.14.14
>= 5.0.0-RC1, <= 5.6.16
Patched versions
3.9.15
4.14.15
5.6.17
Description
Published to the GitHub Advisory Database
Apr 25, 2025
Reviewed
Apr 25, 2025
Published by the National Vulnerability Database
Apr 25, 2025
Last updated
Apr 25, 2025
Impact
This is an additional fix for GHSA-4w8r-3xrw-v25g
This is a high-impact, low-complexity attack vector. To mitigate the issue, users running Craft installations before the fixed versions are encouraged to update to at least that version.
Details
https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432
References
craftcms/cms@e1c8544
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical
https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical
https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/
Credits
Credit to Orange Cyberdefense for discovering a reporting this bug.
References