We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
Reserved 2025-06-19 | Published 2025-06-19 | Updated 2025-06-19 | Assigner crafterCWE-913 Improper Control of Dynamically-Managed Code Resources
Matei "Mal" Badanoiu
docs.craftercms.org/current/security/advisory.html
Support options