Craft CMS Potential Remote Code Execution via Twig SSTI
Package
Affected versions
>= 4.0.0-RC1, <= 4.16.5
>= 5.0.0-RC1, <= 5.8.6
Patched versions
4.16.6
5.8.7
Description
Published by the National Vulnerability Database
Aug 25, 2025
Published to the GitHub Advisory Database
Aug 25, 2025
Reviewed
Aug 25, 2025
Last updated
Nov 27, 2025
Note that users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled for this to work, which is against Craft CMS' recommendations for any non-dev environment.
https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production
Note: This is a follow-up to GHSA-f3cw-hg6r-chfv
Users should update to the patched versions (4.16.6 and 5.8.7) to mitigate the issue.
Resources: craftcms/cms#17612
References