craftcms/cms is vulnerable to Remote Code Execution (RCE)
68
Medium Risk
Affected versions of this package contain an undisclosed remote code execution (RCE) vulnerability. Under certain conditions, an attacker could exploit this flaw to execute arbitrary code on the affected system, potentially leading to full compromise of the application and underlying host. The exact attack vector has not been publicly disclosed, but updating to a patched version is strongly recommended to mitigate the risk.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Remote Code Execution (RCE) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant