← Vulnerability feed

Vulnerability record · CVE-2025-35939 · published 7 May 2025

CVE-2025-35939: Craft CMS unauthenticated session file write enables PHP code injection

Craftcms · Craft Cms

Craft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path is predictable and the content is attacker-controlled, PHP code can be written to a known local file location. This matters because it creates a local file inclusion or execution primitive that can be chained with an independent vulnerability to run code.

6.9 CVSS 4.0 Medium CISA KEV since 2 Jun 2025 EPSS 1.3% · top 30.3% CWE-472 · CWE-472
6.9CVSS 4.0 base score
1.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is unauthenticated and network-reachable, and CISA KEV listing confirms active exploitation, though it requires chaining with a separate vulnerability to achieve code execution.

What it is

Craft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path is predictable and the content is attacker-controlled, PHP code can be written to a known local file location. This matters because it creates a local file inclusion or execution primitive that can be chained with an independent vulnerability to run code.

Impact

An unauthenticated attacker can plant arbitrary PHP code in a known session file on the server. If combined with a separate file inclusion or execution flaw, this yields remote code execution on the Craft CMS host.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector AV:N/PR:N/UI:N. The attacker simply triggers a redirect to the login page and controls the return URL parameter that gets written into the session file.

Exploitation

CVE-2025-35939 is listed in CISA KEV with a due date of 2025-06-23, indicating known exploitation in the wild. EPSS 30-day probability is 0.01317 (69th percentile), so mass scanning is not strongly indicated, but KEV status confirms real-world use.

What to do

  • Upgrade Craft CMS to 5.7.5 or 4.15.3, which contain the fix.
  • Apply the vendor patch referenced in PR 17220 if an immediate upgrade is not possible.
  • Restrict or monitor access to the PHP session directory (/var/lib/php/sessions) and ensure session files are not web-accessible.
  • Review and harden any file inclusion or template rendering paths that could read session files.
  • Follow CISA BOD 22-01 guidance for cloud services or discontinue use if mitigations cannot be applied.

Detection

  • Monitor session files in /var/lib/php/sessions for unexpected PHP tags or code-like content.
  • Alert on requests that set return URL parameters containing PHP code or unusual characters.
  • Watch for chained exploitation attempts that read or include session files via other application endpoints.
  • Audit web server logs for unauthenticated redirect requests with attacker-controlled return URL values.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-35939 to the Known Exploited Vulnerabilities catalog on 2 June 2025 as "Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-35939 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32432Craft CMS unauthenticated remote code execution via code injectionCraft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote co…KEVEPSS 100%analysed9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed8.1CVE-2025-23209Craft CMS code injection RCE with compromised security keyCraft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been comp…KEVEPSS 22%analysed9.8CVE-2024-37843Craft CMS SQL injection via GraphQL API endpointCraft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-rea…EPSS 53%analysed9.8CVE-2023-41892Craft CMS code injection enables unauthenticated remote code executionCraft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, …EPSS 94%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2020-9757SEOmatic for Craft CMS template injection leads to RCEThe SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers c…EPSS 73%analysed9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2025-35939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.