Intel

AIKIDO-2026-10120

craftcms/cms is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)GHSA-v47q-jxvr-p68x Published Feb 5, 2026

68

Medium Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.16.19
Fixed in 4.17.0
5.0.0 - 5.8.23
Fixed in 5.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain an undisclosed remote code execution (RCE) vulnerability. Under certain conditions, an attacker could exploit this flaw to execute arbitrary code on the affected system, potentially leading to full compromise of the application and underlying host. The exact attack vector has not been publicly disclosed, but updating to a patched version is strongly recommended to mitigate the risk.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Remote Code Execution (RCE) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.

How to fix this

Upgrade the craftcms/cms library to the patch version.