{"id":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","summary":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","severity":"high","cwe":["CWE-94"],"vendor":"craftcms","product":"craftcms/cms","ecosystem":"composer","affected":["craftcms/cms >= 5.5.0, <= 5.9.13"],"patched":["craftcms/cms 5.9.14"],"published":"2026-07-09","updated":"2026-07-09","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-86vw-x4ww-x467","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-86vw-x4ww-x467"},{"url":"https://github.com/advisories/GHSA-86vw-x4ww-x467"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-09T13:51:05.149Z","slug":"GHSA-86vw-x4ww-x467","body":"## Overview\n\nThe `actionRenderCardPreview()` method in `FieldsController` passes the `fieldLayoutConfig` POST parameter directly to `Fields::createLayout()` without calling `Component::cleanseConfig()`. This allows Yii2 event handler injection via `on eventName` keys in the config array, leading to arbitrary code execution.\n\nThis is the same vulnerability pattern that was fixed in GHSA-4484-8v2f-5748 (same file, `_fldComponent` method correctly uses `cleanseConfig`), GHSA-qx2q-q59v-wf3j (EntryTypesController), and GHSA-2fph-6v5w-89hh (ElementIndexesController).\n\n## PoC\n\nAs an admin user with a valid session:\n\n```\nPOST /admin/actions/fields/render-card-preview HTTP/1.1\nContent-Type: application/x-www-form-urlencoded\nCookie: CraftSessionId=<session>\n\nfieldLayoutConfig[on+init]=phpinfo&CRAFT_CSRF_TOKEN=<token>\n```\n\nWhen the FieldLayout object is constructed, Yii2 processes the `on init` key as an event handler registration. During `Component::init()`, the `init` event is triggered, calling `phpinfo()`. The phpinfo output (which includes environment variables, potentially containing database credentials and `CRAFT_SECURITY_KEY`) will appear in the response.\n\n## Impact\n\nAn authenticated admin can achieve RCE through Yii2 event handler injection. While this requires admin access (same as GHSA-4484-8v2f-5748, which was rated moderate), it allows arbitrary PHP function execution and information disclosure via phpinfo.\n\n## Affected packages\n\n- `craftcms/cms >= 5.5.0, <= 5.9.13`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `craftcms/cms 5.9.14`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}