Skip to content

Potential Remote Code Execution via Twig SSTI

Moderate
angrybrad published GHSA-crcq-738g-pqvc Aug 25, 2025

Package

composer craftcms/cms (Composer)

Affected versions

>= 4.0.0-RC1, <= 4.16.5
>= 5.0.0-RC1, <= 5.8.6

Patched versions

4.16.6
5.8.7

Description

Note that you must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled for this to work, which is against our recommendations for any non-dev environment.

https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production

Note: This is a follow-up to GHSA-f3cw-hg6r-chfv

Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.

References: #17612

Severity

Moderate

CVE ID

CVE-2025-57811

Weaknesses

No CWEs

Credits