{"id":"CVE-2025-46731","aliases":["GHSA-7c58-g782-9j38"],"url":"https://o3.security/vulnerability/CVE-2025-46731","summary":"Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI","details":"Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.","published":"2025-05-05T19:35:31.347Z","modified":"2026-08-12T03:51:16.502663195Z","cvss":null,"epss":{"score":0.01414,"percentile":0.70673,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.14.13"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.6.15"}],"fix":{"url":"http://github.com/craftcms/cms/pull/17026","label":"craftcms/cms#17026"},"references":[{"type":"WEB","url":"https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46731.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-7c58-g782-9j38"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-f3cw-hg6r-chfv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46731"},{"type":"FIX","url":"http://github.com/craftcms/cms/pull/17026"},{"type":"PACKAGE","url":"https://github.com/craftcms/cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.502663195Z"}}