Description

Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must meet these requirements: have a compromised security key and create an arbitrary file in Craft's /storage/backups folder. With those criteria in place, attackers could create a specific, malicious request to the /updater/restore-db endpoint and execute CLI commands remotely. This issue is fixed in versions 4.16.3 and 5.8.4.

INFO

Published Date :

2025-08-09T01:31:23.974Z

Last Modified :

2025-08-11T13:38:51.609Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-54417 vulnerability.

Vendors Products
Craftcms
  • Craft Cms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-54417.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability