Vulnerability record · CVE-2025-23209 · published 18 January 2025
CVE-2025-23209: Craft CMS code injection RCE with compromised security key
Craftcms · Craft Cms
Craft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been compromised. The vendor patched it in Craft 5.5.8 and 4.13.8. Because exploitation requires a pre-existing key compromise, the flaw is a post-compromise escalation path rather than a standalone entry point.
Description
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remote code execution flaw listed in CISA KEV with a high EPSS percentile, and exploitation leads to full host compromise.
What it is
Craft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been compromised. The vendor patched it in Craft 5.5.8 and 4.13.8. Because exploitation requires a pre-existing key compromise, the flaw is a post-compromise escalation path rather than a standalone entry point.
Impact
An attacker who holds the compromised security key can execute arbitrary code on the Craft server, gaining full control of the application and its data. This can lead to data theft, defacement, or use of the host as a pivot point.
Attack surface
Reachable over the network (AV:N) with no authentication or user interaction required per the CVSS vector, but only when the security key is already compromised. The precondition is key exposure, not a weakness in the request path itself.
Exploitation
CVE-2025-23209 was added to CISA KEV on 2025-02-20 with a remediation due date of 2025-03-13, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.21776 (97.5th percentile), and no ransomware campaign use is documented.
What to do
- Upgrade to Craft CMS 5.5.8 or 4.13.8 immediately.
- If patching is not possible, rotate the security key and verify it has not been exposed.
- Audit for prior security key compromise and treat any exposed key as a breach indicator.
- Restrict network access to Craft admin and application endpoints where feasible.
- Monitor vendor advisories and CISA KEV for updated guidance.
Detection
- Search application and web server logs for unexpected code execution or anomalous requests around Craft endpoints.
- Alert on changes to Craft configuration files or the security key value.
- Hunt for signs of security key exposure in repositories, logs, or backups.
- Correlate host-level process creation events with Craft PHP worker activity for suspicious child processes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-23209 to the Known Exploited Vulnerabilities catalog on 20 February 2025 as "Craft CMS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-23209 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-23209), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.