PT-2025-34691 · Pixel & Tonic · Craft

·

CVE-2025-57811

·

Published

2025-08-25

·

Updated

2025-08-28

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Craft versions 4.0.0-RC1 through 4.16.5 Craft versions 5.0.0-RC1 through 5.8.6
Description: Craft is a platform for creating digital experiences. A remote code execution issue exists due to Server-Side Template Injection (SSTI) in Twig.
Recommendations: Update to Craft version 4.16.6 or later. Update to Craft version 5.8.7 or later.

Exploit

Fix

RCE

Path traversal

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57811
GHSA-CRCQ-738G-PQVC

Affected Products

Craft