Home

Description

Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.

PUBLISHED Reserved 2025-12-01 | Published 2025-12-02 | Updated 2025-12-02 | Assigner Mautic




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-434 Unrestricted Upload of File with Dangerous Type

Product status

Default status
unaffected

<4.4.18, <5.2.9, <6.0.7 (semver)
affected

Credits

Jason Woods (driskell) reporter

Patryk Gruszka (patrykgruszka) remediation reviewer

Jan Linhart (escopecz) remediation reviewer

Jason Woods (driskell) remediation developer

References

github.com/...mautic/security/advisories/GHSA-5xw2-57jx-pgjp

cve.org (CVE-2025-13827)

nvd.nist.gov (CVE-2025-13827)

Download JSON