Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-54417
5.2MEDIUM
What is CVE-2025-54417?
Craft CMS versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 are affected by a vulnerability that allows remote code execution through a compromised security key. An attacker who possesses a compromised security key can create an arbitrary file in the /storage/backups folder. By sending a specially crafted request to the /updater/restore-db endpoint, the attacker can execute CLI commands remotely. This vulnerability has been addressed in versions 4.16.3 and 5.8.4.
Affected Version(s)
cms >= 4.13.8, < 4.16.3 < 4.13.8, 4.16.3
cms >= 5.5.8, < 5.8.4 < 5.5.8, 5.8.4