CVE-2025-32432: Craft CMS Code Injection Vulnerability
Impact
This is an additional fix for https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
This is a high-impact, low-complexity attack vector. To mitigate the issue, users running Craft installations before the fixed versions are encouraged to update to at least that version.
Details
https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432
References
https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical
https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/
Credits
Credit to Orange Cyberdefense for discovering a reporting this bug.
Other sources
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
— CISA
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 5.6.17 - Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 4.14.15 - Upgrade
Upgrade
composer/craftcms/cmsto a version that resolves this vulnerability.Fixed in 3.9.15 - Remove
Remove
composer/craftcms/cmsfrom your environment.Discontinue use or uninstall the product if mitigations are unavailable and you cannot upgrade to a fixed version.
- Compensating control
Apply vendor-provided mitigations per Craft CMS instructions and follow applicable BOD 22-01 guidance for cloud services if you cannot immediately upgrade to a fixed version.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32432?
CVE-2025-32432 has been classified as a high-impact vulnerability.
How do I fix CVE-2025-32432?
To fix CVE-2025-32432, update your Craft CMS installation to version 5.6.17, 4.14.15, or 3.9.15 depending on your current version.
What versions of Craft CMS are affected by CVE-2025-32432?
CVE-2025-32432 affects Craft CMS versions from 5.0.0-RC1 to 5.6.16, 4.0.0-RC1 to 4.14.14, and 3.0.0-RC1 to 3.9.14.
Is CVE-2025-32432 a complex vulnerability?
No, CVE-2025-32432 is considered a low-complexity attack vector.
Should I update my Craft CMS immediately due to CVE-2025-32432?
Yes, it is recommended to update your Craft CMS installation immediately to mitigate the risks associated with CVE-2025-32432.