{"id":"CVE-2025-13827","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-13827","summary":"GrapesJsBuilder File Upload allows all file uploads","details":"### Summary\n\nArbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. \n\n### Impact\n\nIf the media folder is not restricted from running files this can lead to a remote code execution.","published":"2025-12-02T21:11:33Z","modified":"2025-12-02T21:37:53.759277Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mautic/grapes-js-builder-bundle","fixedVersion":"4.4.18"},{"ecosystem":"Packagist","name":"mautic/grapes-js-builder-bundle","fixedVersion":"5.2.9"},{"ecosystem":"Packagist","name":"mautic/grapes-js-builder-bundle","fixedVersion":"6.0.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/mautic/mautic/security/advisories/GHSA-5xw2-57jx-pgjp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13827"},{"type":"PACKAGE","url":"https://github.com/mautic/mautic"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-02T21:37:53.759277Z"}}