CVE-2025-23209

Confirmed PUBLISHED

Potential RCE with a compromised security key in craft/cms

craftcms · cms
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High

At a Glance

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.

cisa
CVE Published
Jan 18, 2025
Exploitation Reported
Feb 20, 2025
CVSS
8.1 High
EPSS
Remote

Affected Versions

Vendor Product Version Status
craftcms
cms

>= 5.0.0-RC1, < 5.5.5

Affected
craftcms
cms

>= 4.0.0-RC1, < 4.13.8

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.