CVE-2025-29790: Contao allows cross-site scripting through SVG uploads
Impact
Users can upload SVG files with malicious code, which is then executed in the back end and/or front end.
Patches
Update to Contao 4.13.54, 5.3.30 or 5.5.6.
Workarounds
Remove svg,svgz from the allowed upload file types in the system settings and from contao.editablefiles in the config.yaml.
References
https://contao.org/en/security-advisories/cross-site-scripting-through-svg-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.5.6 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 5.3.30 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 4.13.54 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.13.54 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.5.6 - Configuration
Remove `svg,svgz` from the allowed upload file types in the system settings.
Contao system settings (allowed upload file types) allowed upload file types = remove svg,svgz - Configuration
In `config.yaml`, remove `svg,svgz` from `contao.editable_files`.
Contao configuration contao.editable_files (config.yaml) = remove svg,svgz
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29790?
CVE-2025-29790 is considered a critical vulnerability due to the potential execution of malicious code from uploaded SVG files.
How do I fix CVE-2025-29790?
To fix CVE-2025-29790, upgrade to Contao versions 4.13.54, 5.3.30, or 5.5.6.
What software is affected by CVE-2025-29790?
CVE-2025-29790 affects various versions of the Contao open-source CMS that allow SVG file uploads.
Can CVE-2025-29790 lead to data loss?
Yes, CVE-2025-29790 can potentially lead to data loss or compromise by allowing execution of harmful code.
Is there a workaround for CVE-2025-29790?
No official workaround for CVE-2025-29790 exists other than upgrading to the fixed versions.