{"id":"GHSA-2vcf-qxv3-2mgw","summary":"Craft CMS has a theoretical bypass for CVE-2025-23209","details":"**Pre-requisites:**\n\n* Have a compromised security key (https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret)\n* Somehow, manage to create an arbitrary file in Craft’s `/storage/backups` folder.\n\nWith those two pieces in place, you could create a specific, malicious request to the `/updater/restore-db` endpoint to execute CLI commands remotely.\n\nFixed in https://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57\n\n-----\n\nReported by Marco O. (segfault)","aliases":["CVE-2025-54417"],"modified":"2025-08-11T14:13:37.935169Z","published":"2025-08-08T19:32:50Z","database_specific":{"github_reviewed_at":"2025-08-08T19:32:50Z","nvd_published_at":"2025-08-09T02:15:37Z","cwe_ids":["CWE-94"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/craftcms/cms/security/advisories/GHSA-2vcf-qxv3-2mgw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23209"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54417"},{"type":"WEB","url":"https://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"affected":[{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.13.8"},{"fixed":"4.16.3"}]}],"versions":["4.13.10","4.13.8","4.13.9","4.14.0","4.14.0.1","4.14.0.2","4.14.1","4.14.10","4.14.11","4.14.11.1","4.14.12","4.14.13","4.14.14","4.14.15","4.14.2","4.14.3","4.14.4","4.14.5","4.14.6","4.14.7","4.14.8","4.14.8.1","4.14.9","4.15.0","4.15.0-beta.1","4.15.0-beta.2","4.15.0.1","4.15.0.2","4.15.1","4.15.2","4.15.3","4.15.4","4.15.5","4.15.6","4.15.6.1","4.15.6.2","4.15.7","4.16.0","4.16.1","4.16.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-2vcf-qxv3-2mgw/GHSA-2vcf-qxv3-2mgw.json"}},{"package":{"name":"craftcms/cms","ecosystem":"Packagist","purl":"pkg:composer/craftcms/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.5.8"},{"fixed":"5.8.4"}]}],"versions":["5.5.10","5.5.8","5.5.9","5.6.0","5.6.0.1","5.6.0.2","5.6.1","5.6.10","5.6.10.1","5.6.10.2","5.6.11","5.6.12","5.6.13","5.6.14","5.6.15","5.6.16","5.6.17","5.6.2","5.6.3","5.6.4","5.6.5","5.6.5.1","5.6.6","5.6.7","5.6.8","5.6.9","5.6.9.1","5.7.0","5.7.0-beta.1","5.7.0-beta.2","5.7.1","5.7.1.1","5.7.10","5.7.11","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.7","5.7.8","5.7.8.1","5.7.8.2","5.7.9","5.8.0","5.8.1","5.8.2","5.8.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-2vcf-qxv3-2mgw/GHSA-2vcf-qxv3-2mgw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}