CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Other sources
Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/yiisoft/yii2to a version that resolves this vulnerability.Fixed in 2.0.52 - Remove
Remove
Yii Frameworkfrom your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Remove
Remove
Yii Framework Giifrom your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Remove
Remove
composer/yiisoft/yii2from your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58136?
CVE-2024-58136 has been classified as a critical vulnerability due to its exploitation in the wild.
How do I fix CVE-2024-58136?
To fix CVE-2024-58136, you should upgrade Yii 2 to version 2.0.52 or later.
What software is affected by CVE-2024-58136?
CVE-2024-58136 affects Yii 2 versions prior to 2.0.52.
What kind of vulnerability is CVE-2024-58136?
CVE-2024-58136 is a vulnerability related to the mishandling of behavior attachments in the Yii framework.
When was CVE-2024-58136 exploited in the wild?
CVE-2024-58136 was reportedly exploited in the wild between February and April 2025.