Impact
A flaw in Craft CMS’s Twig sandbox permits an authenticated user who can access the control panel to craft a malicious Twig template that exploits the yii\base\Component arbitrary function‑call gadget, allowing execution of arbitrary code on the server. This remote code execution threatens confidentiality, integrity, and availability, potentially leading to full system compromise.
Affected Systems
Craft CMS versions 5.0.0-RC1 through 5.10.6 and 4.0.0-RC1 through 4.18.2 are impacted. The vulnerability is fixed in Craft CMS 5.10.7 and 4.18.3.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and because no EPSS rating is provided the exact exploitation probability remains unknown; nevertheless the risk is high given that the attacker only needs authenticated access to the control panel. The vulnerability is not listed in CISA KEV. If an attacker gains control panel privileges they can immediately execute arbitrary code on the host. The likely attack vector is an authenticated remote manipulator with permission to edit templates via the control panel.
OpenCVE Enrichment