Skip to content

Potential authenticated Remote Code Execution via Twig SSTI

Moderate
angrybrad published GHSA-742x-x762-7383 Jan 3, 2026

Package

composer craftcms/cms (Composer)

Affected versions

>= 5.0.0-RC1, <= 5.8.20
>= 4.0.0-RC1, <= 4.16.16

Patched versions

5.8.21
4.16.17

Description

For this to work, you must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled for this to work, which is against our recommendations for any non-dev environment.

https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production

Alternatively, you can have a non-administrator account with allowAdminChanges disabled, but you have access to the System Messages utility.

It is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE.

Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

References:

d82680f

https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04

Severity

Moderate

CVE ID

CVE-2025-68454

Weaknesses

No CWEs

Credits