GHSA-x684-96hh-833x
Craft CMS has a potential RCE with a compromised security key
Quick fix
GHSA-x684-96hh-833x — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^5.5.8Details
### Impact
This is an RCE vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised.
https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret
Anyone running an unpatched version of Craft with a compromised security key is affected.
### Patches
This has been patched in Craft 5.5.8 and 4.13.8.
### Workarounds
If you can't update to a patched version, then rotating your security key and ensuring its privacy will help to migitgate the issue.
### References
https://github.com/craftcms/cms/commit/e59e22b30c9dd39e5e2c7fe02c147bcbd004e603
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0-RC1Fixed in: 5.5.8composer require craftcms/cms:^5.5.84.0.0-RC1Fixed in: 4.13.8composer require craftcms/cms:^4.13.8References
- https://github.com/craftcms/cms/security/advisories/GHSA-x684-96hh-833x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-23209[ADVISORY]
- https://github.com/craftcms/cms/commit/e59e22b30c9dd39e5e2c7fe02c147bcbd004e603[WEB]
- https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-23209[WEB]