Vulnerability record · CVE-2025-35939 · published 7 May 2025
CVE-2025-35939: Craft CMS unauthenticated session file write enables PHP code injection
Craftcms · Craft Cms
Craft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path is predictable and the content is attacker-controlled, PHP code can be written to a known local file location. This matters because it creates a local file inclusion or execution primitive that can be chained with an independent vulnerability to run code.
Description
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw is unauthenticated and network-reachable, and CISA KEV listing confirms active exploitation, though it requires chaining with a separate vulnerability to achieve code execution.
What it is
Craft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path is predictable and the content is attacker-controlled, PHP code can be written to a known local file location. This matters because it creates a local file inclusion or execution primitive that can be chained with an independent vulnerability to run code.
Impact
An unauthenticated attacker can plant arbitrary PHP code in a known session file on the server. If combined with a separate file inclusion or execution flaw, this yields remote code execution on the Craft CMS host.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector AV:N/PR:N/UI:N. The attacker simply triggers a redirect to the login page and controls the return URL parameter that gets written into the session file.
Exploitation
CVE-2025-35939 is listed in CISA KEV with a due date of 2025-06-23, indicating known exploitation in the wild. EPSS 30-day probability is 0.01317 (69th percentile), so mass scanning is not strongly indicated, but KEV status confirms real-world use.
What to do
- Upgrade Craft CMS to 5.7.5 or 4.15.3, which contain the fix.
- Apply the vendor patch referenced in PR 17220 if an immediate upgrade is not possible.
- Restrict or monitor access to the PHP session directory (/var/lib/php/sessions) and ensure session files are not web-accessible.
- Review and harden any file inclusion or template rendering paths that could read session files.
- Follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations cannot be applied.
Detection
- Monitor session files in /var/lib/php/sessions for unexpected PHP tags or code-like content.
- Alert on requests that set return URL parameters containing PHP code or unusual characters.
- Watch for chained exploitation attempts that read or include session files via other application endpoints.
- Audit web server logs for unauthenticated redirect requests with attacker-controlled return URL values.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-35939 to the Known Exploited Vulnerabilities catalog on 2 June 2025 as "Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/craftcms/cms/pull/17220 | Patch |
| https://github.com/craftcms/cms/releases/tag/4.15.3 | Release Notes |
| https://github.com/craftcms/cms/releases/tag/5.7.5 | Release Notes |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-147-01.json | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-35939 | VDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-35939 | US Government Resource |
Track CVE-2025-35939 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-35939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.