Executive brief
Craft CMS contains a code injection vulnerability due to improper validation of the database backup path. This allows remote code execution (RCE) on systems where the security key has been compromised.
Affected products
- Craft CMS Craft CMS 4.x < 4.13.8, 5.x < 5.5.8
Timeline
- 2025-01-17: disclosed
- 2025-02-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-20: exploited
- 2025-01-17: patched: Patched in versions 4.13.8 and 5.5.8