CVE-2025-13828: Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Summary
A non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
Impact
A low-privileged user of the platform can install malicious code to obtain higher privileges.
Other sources
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/mautic/coreto a version that resolves this vulnerability.Fixed in 6.0.7 - Upgrade
Upgrade
composer/mautic/coreto a version that resolves this vulnerability.Fixed in 5.2.9 - Upgrade
Upgrade
composer/mautic/coreto a version that resolves this vulnerability.Fixed in 4.4.18
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13828?
CVE-2025-13828 is considered a low-severity vulnerability affecting Mautic.
How do I fix CVE-2025-13828?
To mitigate CVE-2025-13828, ensure that the enable composer based update flag is ticked in the update settings.
Who is affected by CVE-2025-13828?
CVE-2025-13828 affects users of Mautic who have granted low-privileged users access to the composer functionality.
What is the impact of CVE-2025-13828?
The impact of CVE-2025-13828 is that low-privileged users can install and remove arbitrary packages, potentially introducing malicious code.
Is there a workaround for CVE-2025-13828?
As a workaround for CVE-2025-13828, restrict access to composer functionalities for low-privileged users.