Skip to content

Potential Remote Code Execution via Twig SSTI

Moderate
angrybrad published GHSA-crcq-738g-pqvc Aug 25, 2025

Package

composer craftcms/cms (Composer)

Affected versions

>= 4.0.0-RC1, <= 4.16.5
>= 5.0.0-RC1, <= 5.8.6

Patched versions

4.16.6
5.8.7

Description

You must have administrator access, and ALLOW_ADMIN_CHANGES must be enabled for this to work.

https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production

Note: This is a follow-up to GHSA-f3cw-hg6r-chfv

Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.

References: #17612

Severity

Moderate

CVE ID

CVE-2025-57811

Weaknesses

No CWEs

Credits