Intel

AIKIDO-2026-739799

craftcms/cms is vulnerable to Remote Code Execution

Remote Code ExecutionGHSA-9c4j-cjw3-r3xx Published Yesterday

82

High Risk

This Affects:

PHPcraftcms/cms
5.0.0 - 5.10.12
Fixed in 5.10.13
Are you affected? Scan for Free

TL;DR

Craft CMS 5.10.13 fixes six independently reported security issues. GHSA-5jmw-g85v-7jv2 allowed signed redirect data to reach unsandboxed Twig rendering and execute code; GHSA-9c4j-cjw3-r3xx allowed request-controlled eager-loading callbacks to invoke arbitrary PHP functions; GHSA-hfjh-gw6x-7pv5 allowed installer-supplied site values to expand environment secrets during a database outage; GHSA-4mgp-5vf2-7c9m allowed nested eager-loading criteria to reach a database query and produce blind SQL injection; GHSA-h9jh-v8vc-m5rp allowed lower-privilege content to become stored XSS through Generated Field index values; and GHSA-6fp2-8j9w-7mj8 allowed view-only users to reorder peer-owned nested elements. A deployment within the vulnerable range may be exposed to one or more of these issues depending on its control panel roles, GraphQL and field configuration, and outage conditions.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and grant non-admin users control panel access, render lower-trust content through Generated Fields, or keep the PHP application reachable while its database is unavailable.

Background info

craftcms/cms is vulnerable to Remote Code Execution in versions 5.0.0 - 5.10.12.

How to fix this

Upgrade the craftcms/cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform