{"id":"CVE-2025-54417","aliases":["GHSA-2vcf-qxv3-2mgw"],"url":"https://o3.security/vulnerability/CVE-2025-54417","summary":"Craft contains a theoretical bypass for CVE-2025-23209","details":"Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: \"Craft CMS has a potential RCE with a compromised security key\". To exploit this vulnerability, the project must meet these requirements: have a compromised security key and create an arbitrary file in Craft's /storage/backups folder. With those criteria in place, attackers could create a specific, malicious request to the /updater/restore-db endpoint and execute CLI commands remotely. This issue is fixed in versions 4.16.3 and 5.8.4.","published":"2025-08-09T01:31:23.974Z","modified":"2026-08-08T03:47:55.610532891Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.16.3"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.8.4"}],"fix":{"url":"https://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57","label":"craftcms/cms@a19d46b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54417.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-2vcf-qxv3-2mgw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54417"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/a19d46be78a9ca1ea474012a10e97bed0d787f57"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:55.610532891Z"}}