{"id":"CVE-2025-13828","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-13828","summary":"Mautic user without privileged access to the Marketplace can install and uninstall composer packages","details":"### Summary\n\nA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.\n\n### Impact\n\nA low-privileged user of the platform can install malicious code to obtain higher privileges.","published":"2025-12-02T21:10:39Z","modified":"2025-12-02T21:37:54.594242Z","cvss":null,"epss":{"score":0.00246,"percentile":0.16078,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"4.4.18"},{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"5.2.9"},{"ecosystem":"Packagist","name":"mautic/core","fixedVersion":"6.0.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/mautic/mautic/security/advisories/GHSA-3fq7-c5m8-g86x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13828"},{"type":"PACKAGE","url":"https://github.com/mautic/mautic"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-12-02T21:37:54.594242Z"}}