Intel

AIKIDO-2026-465129

craftcms/cms is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-9wcj-wqqh-cqvg Published Yesterday

82

High Risk

This Affects:

PHPcraftcms/cms
5.0.0 - 5.10.11
Fixed in 5.10.12
Are you affected? Scan for Free

TL;DR

Craft CMS 5.10.12 fixes three independently reported issues. GHSA-qj4v-m29p-fj4m allowed stringified field-layout configuration to bypass cleansing and restore unsafe Yii behavior or event keys after decoding, leading to code execution. GHSA-jqf5-vfg6-8cx5 allowed a non-admin user administrator to activate a deactivated administrator account without the required admin-target check. GHSA-9wcj-wqqh-cqvg allowed asset transform criteria to select an arbitrary class at the normalization sink, providing a path to code execution. A deployment within the vulnerable range may be exposed to one or more of these issues when untrusted users have the relevant control panel permissions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and untrusted authenticated users can access field-layout configuration, view assets through the control panel, or administrate users.

Background info

craftcms/cms is vulnerable to Remote Code Execution in versions 5.0.0 - 5.10.11.

How to fix this

Upgrade the craftcms/cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform