Craft CMS: Authenticated RCE through Twig sandbox escape
Craft CMS contains a vulnerability in its Twig sandbox mechanism that allows authenticated users with control panel access to execute remote code. The issue arises because the sandbox's allowlisting permits dangerous functionality from the Yii framework, specifically through a known arbitrary function call gadget in yii\base\Component. This enables malicious Twig templates to bypass sandbox restrictions and achieve remote code execution (RCE).
AI Analysis
Technical Summary
The Twig sandbox in Craft CMS implements a SecurityPolicy that allowlists classes, methods, and properties for use in user-defined templates. However, the allowlisting mechanism is overly permissive, allowing all methods and properties of an allowed class and its subclasses. Craft CMS marks the ElementInterface as safe, and since Element extends craft\base\Component, which in turn extends yii\base\Component, the sandbox inadvertently permits access to a dangerous function call gadget in yii\base\Component. This gadget has been previously exploited in multiple Craft CMS RCE vulnerabilities. Consequently, an authenticated attacker with control panel access can render a malicious Twig template to achieve remote code execution, even when the Twig sandbox is enabled.
Potential Impact
An authenticated attacker with permission to access the Craft CMS control panel can exploit this vulnerability to execute arbitrary code on the server. This compromises the confidentiality, integrity, and availability of the affected system. The vulnerability bypasses the intended restrictions of the Twig sandbox, enabling remote code execution despite sandbox protections.
Mitigation Recommendations
A patch is available for this vulnerability. It is recommended to apply the official fix provided by Craft CMS to remediate the issue. Until patched, restrict control panel access to trusted users only. Review and update Twig sandbox allowlists to avoid permitting dangerous classes or methods. Monitor vendor advisories for updated remediation guidance.
Craft CMS: Authenticated RCE through Twig sandbox escape
Description
Craft CMS contains a vulnerability in its Twig sandbox mechanism that allows authenticated users with control panel access to execute remote code. The issue arises because the sandbox's allowlisting permits dangerous functionality from the Yii framework, specifically through a known arbitrary function call gadget in yii\base\Component. This enables malicious Twig templates to bypass sandbox restrictions and achieve remote code execution (RCE).
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Twig sandbox in Craft CMS implements a SecurityPolicy that allowlists classes, methods, and properties for use in user-defined templates. However, the allowlisting mechanism is overly permissive, allowing all methods and properties of an allowed class and its subclasses. Craft CMS marks the ElementInterface as safe, and since Element extends craft\base\Component, which in turn extends yii\base\Component, the sandbox inadvertently permits access to a dangerous function call gadget in yii\base\Component. This gadget has been previously exploited in multiple Craft CMS RCE vulnerabilities. Consequently, an authenticated attacker with control panel access can render a malicious Twig template to achieve remote code execution, even when the Twig sandbox is enabled.
Potential Impact
An authenticated attacker with permission to access the Craft CMS control panel can exploit this vulnerability to execute arbitrary code on the server. This compromises the confidentiality, integrity, and availability of the affected system. The vulnerability bypasses the intended restrictions of the Twig sandbox, enabling remote code execution despite sandbox protections.
Mitigation Recommendations
A patch is available for this vulnerability. It is recommended to apply the official fix provided by Craft CMS to remediate the issue. Until patched, restrict control panel access to trusted users only. Review and update Twig sandbox allowlists to avoid permitting dangerous classes or methods. Monitor vendor advisories for updated remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-f5wm-88jv-g5hx
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7573bfbf8831d539d943e0
Added to database: 08/07/2026, 05:57:19 UTC
Last enriched: 08/07/2026, 06:26:06 UTC
Last updated: 08/07/2026, 06:26:06 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.