Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-54417
Currently unrated
What is CVE-2025-54417?
Craft CMS versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 are affected by a vulnerability that allows remote code execution through a compromised security key. An attacker who possesses a compromised security key can create an arbitrary file in the /storage/backups folder. By sending a specially crafted request to the /updater/restore-db endpoint, the attacker can execute CLI commands remotely. This vulnerability has been addressed in versions 4.16.3 and 5.8.4.