Intel

AIKIDO-2026-292184

craftcms/cms is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-5r92-75j8-c534 Published Yesterday

82

High Risk

This Affects:

PHPcraftcms/cms
4.8.0 - 4.18.5
Fixed in 4.18.6
5.0.0 - 5.10.12
Fixed in 5.10.13
Are you affected? Scan for Free

TL;DR

Craft signs a license-shun cookie with the same key and format used to validate signed redirect parameters. An authenticated low-privilege user can transplant the signed cookie envelope into a redirect parameter, which then passes signature validation. During login the validated bytes are rendered as an unsandboxed Twig template, enabling arbitrary OS command execution. The fix restricts the signed cookie fields to safe MD5 and integer values so attacker-controlled Twig cannot be placed in the reusable signed envelope.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and have password-authenticated user accounts without active two-factor authentication.

Background info

craftcms/cms is vulnerable to Remote Code Execution in versions 4.8.0 - 4.18.5 and 5.0.0 - 5.10.12.

How to fix this

Upgrade the craftcms/cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform