Arbitrary Package Installation Vulnerability in Mautic by Mautic
CVE-2025-13828
What is CVE-2025-13828?
A vulnerability exists in the Mautic platform where a non-privileged user can install and remove arbitrary packages via Composer. This issue arises even when the 'enable composer-based updates' option is disabled in the update settings. As a result, attackers could exploit this flaw to install malicious code, potentially allowing them to escalate privileges within the system. This presents a significant security risk, as unauthorized code execution can lead to further exploitation and compromise of the affected systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mautic <4.4.18, <5.2.9, <6.0.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
