Vulnerability record · CVE-2024-58136 · published 10 April 2025
CVE-2024-58136: Yii 2 behavior attachment flaw enables remote code execution
Yiiframework · Yii
Yii 2 before 2.0.52 mishandles attaching a behavior defined by an __class array key, a regression of CVE-2024-4990. The flaw allows attacker-controlled input to influence class instantiation, which is why it carries a critical CVSS score and was exploited in the wild from February through April 2025.
Description
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, confirmed in-the-wild exploitation, KEV listing and a very high EPSS score make this an urgent patch.
What it is
Yii 2 before 2.0.52 mishandles attaching a behavior defined by an __class array key, a regression of CVE-2024-4990. The flaw allows attacker-controlled input to influence class instantiation, which is why it carries a critical CVSS score and was exploited in the wild from February through April 2025.
Impact
An unauthenticated remote attacker can achieve code execution in the context of the affected application, gaining full control over confidentiality, integrity and availability of the host.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or parameter, so the exact request path must be determined from the application's use of behaviors.
Exploitation
CISA added it to KEV on 2025-05-02 with a 2025-05-23 remediation due date, and EPSS gives a 30-day probability of 0.87634 (99.75th percentile). References include an exploit-tagged third-party advisory describing an in-the-wild campaign, and the description states it was exploited in the wild in February through April 2025.
What to do
- Upgrade Yii 2 to 2.0.52 or later, which contains the patch commits referenced in the advisory.
- If immediate upgrade is not possible, follow the vendor advisory and CISA BOD 22-01 guidance, including discontinuing use of the product where mitigations are unavailable.
- Audit application code for behaviors attached from user-controlled input, especially arrays containing an __class key, and remove that pattern.
- Treat any internet-facing Yii 2 instance below 2.0.52 as compromised until logs are reviewed, given confirmed in-the-wild exploitation.
Detection
- Review web and application logs for requests that supply array parameters containing __class or behavior configuration keys.
- Hunt for unexpected process creation, outbound connections or file writes originating from the web server process.
- Check for signs of post-exploitation activity on hosts running Yii 2 below 2.0.52, including new files in web-accessible directories and modified application code.
- Inventory Yii 2 versions across internet-facing and internal applications to identify unpatched instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-58136 to the Known Exploited Vulnerabilities catalog on 2 May 2025 as "Yiiframework Yii Improper Protection of Alternate Path Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 May 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12 | Patch |
| https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52 | Issue Tracking |
| https://github.com/yiisoft/yii2/pull/20232 | Patch |
| https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709 | Issue Tracking |
| https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 | Vendor Advisory |
| https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136 | US Government Resource |
Track CVE-2024-58136 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-58136), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.