{"id":"CVE-2024-56145","aliases":["GHSA-2p6p-9rc9-62j9"],"url":"https://o3.security/vulnerability/CVE-2024-56145","summary":"RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms","details":"Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.","published":"2024-12-18T20:37:34.301Z","modified":"2026-08-12T03:51:35.583538022Z","cvss":null,"epss":{"score":0.97446,"percentile":0.99894,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2025-06-02","dueDate":"2025-06-23","knownRansomwareCampaignUse":false},"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.5.2"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.13.2"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"3.9.14"}],"fix":{"url":"https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3","label":"craftcms/cms@82e893f"},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-56145"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/56xxx/CVE-2024-56145.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56145"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3"},{"type":"EVIDENCE","url":"https://github.com/Chocapikk/CVE-2024-56145"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.583538022Z"}}