{"id":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","summary":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","severity":"high","cwe":["CWE-915"],"vendor":"craftcms","product":"craftcms/cms","ecosystem":"composer","affected":["craftcms/cms >= 5.0.0-RC1, < 5.10.6","craftcms/cms >= 4.0.0-RC1, < 4.18.2"],"patched":["craftcms/cms 5.10.6","craftcms/cms 4.18.2"],"published":"2026-08-06","updated":"2026-08-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-265m-7826-wjqm","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-265m-7826-wjqm"},{"url":"https://github.com/craftcms/cms/commit/353b5d676c88a854c9f6409ad83b837ca0c0e8da"},{"url":"https://github.com/craftcms/cms/commit/789789dc9e2a4e2f2562f51aaf879fb7757d8340"},{"url":"https://github.com/craftcms/cms/releases/tag/4.18.2"},{"url":"https://github.com/craftcms/cms/releases/tag/5.10.6"},{"url":"https://github.com/advisories/GHSA-265m-7826-wjqm"}],"tags":["ghsa","composer"],"ingestedAt":"2026-08-06T21:04:21.915Z","slug":"GHSA-265m-7826-wjqm","body":"## Overview\n\nCraft CMS has an authenticated remote code execution issue in the control panel element-search condition handling.\n\nCraft cleans the outer request-controlled condition array with `Component::cleanseConfig()`, but `Conditions::createCondition()` later decodes and merges the JSON string in `condition.config` without re-running `cleanseConfig()` on the decoded/merged configuration.\n\nBecause `condition.config` is a JSON string during the first cleanse, Yii special config keys such as `as` ... and `on` ... can be hidden inside it. After JSON decoding, those keys reach FieldLayout object creation and are interpreted by Yii as behavior/event configuration.\n\nThe RCE is semi-blind: the trigger endpoint returns a normal JSON response, and the command output is verified via a server-side file-write side effect retrieved in a subsequent request.\n\n## Preconditions\n\n- The attacker needs an authenticated Craft control panel session.\n- A valid CSRF token is required.\n\n## Impact\n\nAn authenticated control panel user can inject Yii behavior/event configuration after Craft’s intended config cleanse boundary. In the confirmed local lab, this led to command execution as the PHP/web user.\n\nPotential attacker impact:\n- Execute operating system commands as the PHP/web user.\n- Read Craft secrets, environment variables, and application configuration.\n- Access database credentials and stored site content.\n- Modify site content, users, and application state.\n- Pivot to internal services reachable from the Craft host or container.\n- Cause denial of service or establish persistence depending on deployment permissions.\n\n## Affected packages\n\n- `craftcms/cms >= 5.0.0-RC1, < 5.10.6`\n- `craftcms/cms >= 4.0.0-RC1, < 4.18.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `craftcms/cms 5.10.6`\n- `craftcms/cms 4.18.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}