Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-54417

Currently unrated

Key Information:

Status
Vendor
CVE Published:
9 August 2025

What is CVE-2025-54417?

Craft CMS versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 are affected by a vulnerability that allows remote code execution through a compromised security key. An attacker who possesses a compromised security key can create an arbitrary file in the /storage/backups folder. By sending a specially crafted request to the /updater/restore-db endpoint, the attacker can execute CLI commands remotely. This vulnerability has been addressed in versions 4.16.3 and 5.8.4.

References

Timeline

  • Vulnerability published

.
CVE-2025-54417 : Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic