SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
Description SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Title Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published:

Updated: 2025-12-02T17:12:20.703Z

Reserved: 2025-12-01T15:20:25.618Z

Link: CVE-2025-13828

cve-icon Vulnrichment

Updated: 2025-12-02T17:12:06.655Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-02T17:16:04.080

Modified: 2025-12-02T17:16:29.163

Link: CVE-2025-13828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.