Home

Description

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

PUBLISHED Reserved 2025-12-17 | Published 2026-01-05 | Updated 2026-01-06 | Assigner GitHub_M




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Product status

>= 5.0.0-RC1, < 5.8.21
affected

>= 4.0.0-RC1, < 4.16.17
affected

References

github.com/...ms/cms/security/advisories/GHSA-255j-qw47-wjh5 exploit

github.com/...ms/cms/security/advisories/GHSA-255j-qw47-wjh5

github.com/...ommit/27f55886098b56c00ddc53b69239c9c9192252c7

github.com/...ommit/6e608a1a5bfb36943f94f584b7548ca542a86fef

github.com/...ommit/ec43c497edde0b2bf2e39a119cded2e55f9fe593

github.com/craftcms/cms/blob/5.x/CHANGELOG.md

cve.org (CVE-2025-68455)

nvd.nist.gov (CVE-2025-68455)

Download JSON