GHSA-265m-7826-wjqm
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
Quick fix
GHSA-265m-7826-wjqm — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^5.10.6 Details
Craft CMS has an authenticated remote code execution issue in the control panel element-search condition handling.
Craft cleans the outer request-controlled condition array with `Component::cleanseConfig()`, but `Conditions::createCondition()` later decodes and merges the JSON string in `condition.config` without re-running `cleanseConfig()` on the decoded/merged configuration.
Because `condition.config` is a JSON string during the first cleanse, Yii special config keys such as `as` ... and `on` ... can be hidden inside it. After JSON decoding, those keys reach FieldLayout object creation and are interpreted by Yii as behavior/event configuration.
The RCE is semi-blind: the trigger endpoint returns a normal JSON response, and the command output is verified via a server-side file-write side effect retrieved in a subsequent request.
## Preconditions
- The attacker needs an authenticated Craft control panel session. - A valid CSRF token is required.
## Impact
An authenticated control panel user can inject Yii behavior/event configuration after Craft’s intended config cleanse boundary. In the confirmed local lab, this led to command execution as the PHP/web user.
Potential attacker impact: - Execute operating system commands as the PHP/web user. - Read Craft secrets, environment variables, and application configuration. - Access database credentials and stored site content. - Modify site content, users, and application state. - Pivot to internal services reachable from the Craft host or container. - Cause denial of service or establish persistence depending on deployment permissions.
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0-RC1 Fixed in: 5.10.6 composer require craftcms/cms:^5.10.6 4.0.0-RC1 Fixed in: 4.18.2 composer require craftcms/cms:^4.18.2 References
- https://github.com/craftcms/cms/security/advisories/GHSA-265m-7826-wjqm [WEB]
- https://github.com/craftcms/cms/commit/353b5d676c88a854c9f6409ad83b837ca0c0e8da [WEB]
- https://github.com/craftcms/cms/commit/789789dc9e2a4e2f2562f51aaf879fb7757d8340 [WEB]
- https://github.com/craftcms/cms [PACKAGE]
- https://github.com/craftcms/cms/releases/tag/4.18.2 [WEB]
- https://github.com/craftcms/cms/releases/tag/5.10.6 [WEB]