Craft CMS Potential Remote Code Execution via Twig SSTI
Package
Affected versions
>= 4.0.0-RC1, <= 4.16.5
>= 5.0.0-RC1, <= 5.8.6
Patched versions
4.16.6
5.8.7
Description
Published by the National Vulnerability Database
Aug 25, 2025
Published to the GitHub Advisory Database
Aug 25, 2025
Reviewed
Aug 25, 2025
Last updated
Aug 26, 2025
You must have administrator access, and
ALLOW_ADMIN_CHANGES
must be enabled for this to work.https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production
Note: This is a follow-up to GHSA-f3cw-hg6r-chfv
Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.
References: craftcms/cms#17612
References