CVE-2025-50706: Code Injection
Published Aug 5, 2025
·Updated
An issue in ThinkPHP Framework v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function.
Other sources
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
— MITRE
Affected Software
3 affected components
ThinkPHP ThinkPHP
composer/topthink/framework<=5.1.41
ThinkPHP ThinkPHP=5.1.0
Event History
Aug 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50706?
CVE-2025-50706 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2025-50706?
To fix CVE-2025-50706, update to the latest version of ThinkPHP that addresses this vulnerability.
3
What type of attack does CVE-2025-50706 facilitate?
CVE-2025-50706 allows a remote attacker to execute arbitrary code on the affected server.
4
Which versions of ThinkPHP are affected by CVE-2025-50706?
CVE-2025-50706 affects ThinkPHP version 5.1 and potentially earlier versions.
5
Is CVE-2025-50706 being actively exploited?
Currently, there are no confirmed reports of active exploitation of CVE-2025-50706, but its high severity warrants urgent attention.