Executive brief
Craft CMS, a popular content management system, contains a vulnerability that allows an administrative user to execute arbitrary code on the server. By sending a specially crafted request to the field layout preview component, an attacker can bypass security checks and run unauthorized commands. This could lead to a full system takeover, exposure of sensitive database credentials, and complete disruption of the website's operations.
Technical details
The vulnerability exists in the `actionRenderCardPreview()` method within `FieldsController`, which passes the `fieldLayoutConfig` POST parameter directly to `Fields::createLayout()` without invoking `Component::cleanseConfig()`. This omission allows an attacker to perform Yii2 event handler injection by including 'on eventName' keys in the configuration array. When the `FieldLayout` object is instantiated, the injected event (such as 'init') is triggered, leading to the execution of arbitrary PHP functions. Exploitation requires an authenticated session with administrative privileges and can result in full remote code execution and information disclosure. The issue is addressed in version 5.9.14.
Affected products
- Pixel & Tonic Craft CMS >= 5.5.0, <= 5.9.13
Timeline
- 2026-06-02: disclosed: Reported to vendor via GitHub Advisory process
- 2026-07-09: advisory: GitHub Advisory published
- 2026-07-09: patched: Fix released in version 5.9.14