← Vulnerability feed

Vulnerability record · CVE-2024-58136 · published 10 April 2025

CVE-2024-58136: Yii 2 behavior attachment flaw enables remote code execution

Yiiframework · Yii

Yii 2 before 2.0.52 mishandles attaching a behavior defined by an __class array key, a regression of CVE-2024-4990. The flaw allows attacker-controlled input to influence class instantiation, which is why it carries a critical CVSS score and was exploited in the wild from February through April 2025.

9.8 CVSS 3.1 Critical CISA KEV since 2 May 2025 EPSS 88% · top 0.2% CWE-424 · CWE-424
9.8CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction, confirmed in-the-wild exploitation, KEV listing and a very high EPSS score make this an urgent patch.

What it is

Yii 2 before 2.0.52 mishandles attaching a behavior defined by an __class array key, a regression of CVE-2024-4990. The flaw allows attacker-controlled input to influence class instantiation, which is why it carries a critical CVSS score and was exploited in the wild from February through April 2025.

Impact

An unauthenticated remote attacker can achieve code execution in the context of the affected application, gaining full control over confidentiality, integrity and availability of the host.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or parameter, so the exact request path must be determined from the application's use of behaviors.

Exploitation

CISA added it to KEV on 2025-05-02 with a 2025-05-23 remediation due date, and EPSS gives a 30-day probability of 0.87634 (99.75th percentile). References include an exploit-tagged third-party advisory describing an in-the-wild campaign, and the description states it was exploited in the wild in February through April 2025.

What to do

  • Upgrade Yii 2 to 2.0.52 or later, which contains the patch commits referenced in the advisory.
  • If immediate upgrade is not possible, follow the vendor advisory and CISA BOD 22-01 guidance, including discontinuing use of the product where mitigations are unavailable.
  • Audit application code for behaviors attached from user-controlled input, especially arrays containing an __class key, and remove that pattern.
  • Treat any internet-facing Yii 2 instance below 2.0.52 as compromised until logs are reviewed, given confirmed in-the-wild exploitation.

Detection

  • Review web and application logs for requests that supply array parameters containing __class or behavior configuration keys.
  • Hunt for unexpected process creation, outbound connections or file writes originating from the web server process.
  • Check for signs of post-exploitation activity on hosts running Yii 2 below 2.0.52, including new files in web-accessible directories and modified application code.
  • Inventory Yii 2 versions across internet-facing and internal applications to identify unpatched instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-58136 to the Known Exploited Vulnerabilities catalog on 2 May 2025 as "Yiiframework Yii Improper Protection of Alternate Path Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 May 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-58136 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-15148Yii 2 unserialize() of untrusted input enables remote code executionYii 2 before 2.0.38 is vulnerable to remote code execution when an application calls unserialize() on arbitrary user input, a classic CWE-502 deseria…EPSS 79%analysed9.8CVE-2023-47130Yiiframework yii deserialization of untrusted data vulnerabilityYii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `un…EPSS 3.1%9.8CVE-2015-5467Yiiframework yii path traversal vulnerabilityweb\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.EPSS 0.88%9.8CVE-2023-26750Yiiframework yii sql injection vulnerabilitySQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the run…EPSS 1.8%9.8CVE-2022-41922Yiiframework yii deserialization of untrusted data vulnerability`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. T…EPSS 1.2%9.8CVE-2018-7269Yiiframework yii sql injection vulnerabilityThe findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a…EPSS 1.9%9.8CVE-2018-8073Yiiframework yii code injection vulnerabilityYii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis e…EPSS 1.6%9.1CVE-2024-4990Yii2 Component __set() allows arbitrary class instantiationIn yiisoft/yii2 version 2.0.48, the base Component class __set() magic method fails to validate that a value is a valid Behavior class name or config…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2024-58136), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.