Craft CMS has a theoretical bypass for CVE-2025-23209
Package
Affected versions
>= 4.13.8, < 4.16.3
>= 5.5.8, < 5.8.4
Patched versions
4.16.3
5.8.4
Description
Published to the GitHub Advisory Database
Aug 8, 2025
Reviewed
Aug 8, 2025
Published by the National Vulnerability Database
Aug 9, 2025
Last updated
Aug 11, 2025
Pre-requisites:
/storage/backupsfolder.With those two pieces in place, you could create a specific, malicious request to the
/updater/restore-dbendpoint to execute CLI commands remotely.Fixed in craftcms/cms@a19d46b
Reported by Marco O. (segfault)
References