Junglewise Threat Intelligence

CVE-2024-58136: yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key

CVE-2024-58136 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2025-04-10

Technologies: yiisoft/yii2 (Packagist), Pixel & Tonic Craft CMS. Vendors: Packagist.

Executive brief

Yii Framework 2 mishandles the attaching of behavior defined by an __class array key, resulting in an improper protection of alternate path vulnerability. This flaw is a regression of CVE-2024-4990 and allows remote attackers to execute arbitrary code. The vulnerability also impacts downstream products such as Craft CMS.

Affected products

  • Yiiframework Yii 2 before 2.0.52
  • Pixel & Tonic Craft CMS

Timeline

  • 2025-04-09: disclosed: NVD Published Date
  • 2025-05-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02: exploited: Exploitation in the wild began as early as February 2025
  • 2025-04-28: patched: Yii 2.0.52 released to address the regression

Related threats