Executive brief
Bolt CMS vulnerable to authenticated remote code execution
Affected products
- Packagist bolt/bolt
Junglewise Threat Intelligence
CVE-2025-34086 · Severity: medium · CVSS 4 · Published 2025-07-03
Technologies: bolt/bolt (Packagist). Vendors: Packagist.
Bolt CMS vulnerable to authenticated remote code execution