highVulnerability

GHSA-265m-7826-wjqm

Craft CMS has an authenticated remote code execution issue in the control panel element-search condition handling. Craft cleans the outer request-controlled condition array with `Component::cleanseConfig()`, but `Conditions::createCondition()` later decodes and merges the JSON string in `condition.config` without re-running `cleanseConfig()` on the decoded/merged configuration. Because `condition.config` is a JSON string during the first cleanse, Yii special config keys such as `as` ... and `on` ... can be hidden inside it. After JSON decoding, those keys reach FieldLayout object creation and are interpreted by Yii as behavior/event configuration. The RCE is semi-blind: the trigger endpoint returns a normal JSON response, and the command output is verified via a server-side file-write side effect retrieved in a subsequent request. ## Preconditions - The attacker needs an authenticated Craft control panel session. - A valid CSRF token is required. ## Impact An authenticated control panel user can inject Yii behavior/event configuration after Craft’s intended config cleanse boundary. In the confirmed local lab, this led to command execution as the PHP/web user. Potential attacker impact: - Execute operating system commands as the PHP/web user. - Read Craft secrets, environment variables, and application configuration. - Access database credentials and stored site content. - Modify site content, users, and application state. - Pivot to internal services reachable from the Craft host or container. - Cause denial of service or establish persistence depending on deployment permissions.

Properties

ghsa_id
GHSA-265m-7826-wjqm
summary
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
severity
high
cve_id
GHSA-265m-7826-wjqm
is_ghsa_only
true
ghsa_published
2026-08-06T20:45:00Z
source_url
https://github.com/advisories/GHSA-265m-7826-wjqm
ghsa_updated
2026-08-06T20:45:01Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/craftcms/cms

AFFECTS (1)

[Software]composer/craftcms/cms

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-265m-7826-wjqm — Ninja Signal Threat Intelligence | Ninja Signal