Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-54417

5.2MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
9 August 2025

What is CVE-2025-54417?

Craft CMS versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 are affected by a vulnerability that allows remote code execution through a compromised security key. An attacker who possesses a compromised security key can create an arbitrary file in the /storage/backups folder. By sending a specially crafted request to the /updater/restore-db endpoint, the attacker can execute CLI commands remotely. This vulnerability has been addressed in versions 4.16.3 and 5.8.4.

Affected Version(s)

cms >= 4.13.8, < 4.16.3 < 4.13.8, 4.16.3

cms >= 5.5.8, < 5.8.4 < 5.5.8, 5.8.4

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.
CVE-2025-54417 : Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic