Impact
Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign authenticated user cookies with a key shared for signed redirect parameters. When an attacker whose account is not an administrator sets a signed cookie via the license‑shun endpoint, the system accepts the cookie's multipart content, rewrites it into a redirect parameter, and upon a successful login it renders the signed data as a Twig template. Twig’s map filter permits a string callback whereby PHP’s system() is invoked, allowing an attacker to execute arbitrary operating‑system commands as the web‑server user. The vulnerability therefore enables remote code execution without requiring administrative privileges, provided the attacker has a password‑authenticated account without active 2FA and standard request configuration.
Affected Systems
Craft CMS server installations running any of the following versions are affected: Craft CMS 4.8.0 through 4.18.5 inclusive, and Craft CMS 5.0.0 through 5.10.12 inclusive. The issue was introduced in 4.8.0 and 5.0.0 and remediated in versions 4.18.6 and 5.10.13 respectively.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability; the EPSS score is below 1%, suggesting current exploitation activity is rare, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is remote via the web interface: an attacker can create or use a normal account, exploit the license‑shun endpoint to craft a signed cookie, then trigger a login that causes Craft to validate and render the cookie’s content as part of a Twig template. Successful exploitation would give the attacker operating‑system command execution as the web‑server process, enabling full compromise of the affected system. The lack of administrative privilege requirement means any user can perform this attack, widening its potential impact.
OpenCVE Enrichment