Craft CMS has a potential RCE with a compromised security key
Package
Affected versions
>= 5.0.0-RC1, < 5.5.5
>= 4.0.0-RC1, < 4.13.8
Patched versions
5.5.8
4.13.8
Description
Published by the National Vulnerability Database
Jan 18, 2025
Published to the GitHub Advisory Database
Jan 21, 2025
Reviewed
Jan 21, 2025
Impact
This is an RCE vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised.
https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret
Anyone running an unpatched version of Craft with a compromised security key is affected.
Patches
This has been patched in Craft 5.5.8 and 4.13.8.
Workarounds
If you can't update to a patched version, then rotating your security key and ensuring its privacy will help to migitgate the issue.
References
craftcms/cms@e59e22b
References