Executive brief
Mautic, a popular open-source marketing automation platform, contains a vulnerability in its package management system that allows low-privileged users to install and remove arbitrary software packages even when administrators have disabled this feature. An attacker with basic user access can exploit this to install malicious code and escalate privileges to administrator level, potentially gaining full control of the platform and access to all customer data stored within it.
Technical details
This is a privilege escalation vulnerability in Mautic's Marketplace composer integration. A low-privileged user can bypass access controls and invoke composer package installation/removal operations through the platform's API or interface, regardless of whether the administrator has disabled composer-based updates in the settings. The vulnerability affects Mautic versions 4.0 and later. An authenticated low-privilege user (network attack vector, low complexity) can install arbitrary malicious packages that execute with the application's privileges, achieving remote code execution and subsequent privilege escalation. Patches are available in versions 4.4.18, 5.2.9, and 6.0.7.
Affected products
- Mautic Mautic >=4.0, <4.4.18; 5.0-5.2.8; 6.0-6.0.6
Timeline
- 2025-12-02: disclosed: Published via GitHub Security Advisory GHSA-3fq7-c5m8-g86x and CVE-2025-13828
- 2025-12-02: patched: Fixes released in versions 4.4.18, 5.2.9, and 6.0.7