CVE-2025-6384

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*

History

16 Dec 2025, 16:08

Type Values Removed Values Added
CPE cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*
References () https://docs.craftercms.org/current/security/advisory.html#cv-2025061901 - () https://docs.craftercms.org/current/security/advisory.html#cv-2025061901 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Craftercms craftercms
Craftercms

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de control inadecuado de recursos de código gestionados dinámicamente en Crafter Studio de CrafterCMS permite a los desarrolladores autenticados ejecutar comandos del sistema operativo mediante Groovy Sandbox Bypass. Al insertar elementos maliciosos de Groovy, un atacante puede eludir las restricciones de la Sandbox y obtener RCE (ejecución remota de código). Este problema afecta a CrafterCMS desde la versión 4.0.0 hasta la 4.2.2.

19 Jun 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-19 21:15

Updated : 2025-12-16 16:08


NVD link : CVE-2025-6384

Mitre link : CVE-2025-6384

CVE.ORG link : CVE-2025-6384


JSON object : View

Products Affected

craftercms

  • craftercms
CWE
CWE-913

Improper Control of Dynamically-Managed Code Resources