CVE-2025-57811: Craft Potential Remote Code Execution via Twig SSTI
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.
Other sources
You must have administrator access, and ALLOWADMINCHANGES must be enabled for this to work.
https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production
Note: This is a follow-up to GHSA-f3cw-hg6r-chfv
Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.
References: https://github.com/craftcms/cms/pull/17612
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57811?
The severity of CVE-2025-57811 is critical due to the potential for remote code execution.
How do I fix CVE-2025-57811?
To fix CVE-2025-57811, upgrade to a version of Craft CMS that is not vulnerable, specifically those beyond 5.8.6.
What versions are affected by CVE-2025-57811?
CVE-2025-57811 affects Craft CMS versions from 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6.
What is the nature of the vulnerability in CVE-2025-57811?
CVE-2025-57811 is a remote code execution vulnerability caused by Server-Side Template Injection (SSTI) via Twig.
Is CVE-2025-57811 a follow-up to any previous vulnerabilities?
Yes, CVE-2025-57811 is a follow-up to CVE-2024-52293.