GHSA-86vw-x4ww-x467High▾ TwilightCraft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The actionRenderCardPreview() method in FieldsController passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). This allows Yii2 event handler injection via on eventName keys in the config array, leading to arbitrary code execution.
This is the same vulnerability pattern that was fixed in GHSA-4484-8v2f-5748 (same file, _fldComponent method correctly uses cleanseConfig), GHSA-qx2q-q59v-wf3j (EntryTypesController), and GHSA-2fph-6v5w-89hh (ElementIndexesController).
As an admin user with a valid session:
POST /admin/actions/fields/render-card-preview HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Cookie: CraftSessionId=<session>
fieldLayoutConfig[on+init]=phpinfo&CRAFT_CSRF_TOKEN=<token>
When the FieldLayout object is constructed, Yii2 processes the on init key as an event handler registration. During Component::init(), the init event is triggered, calling phpinfo(). The phpinfo output (which includes environment variables, potentially containing database credentials and CRAFT_SECURITY_KEY) will appear in the response.
An authenticated admin can achieve RCE through Yii2 event handler injection. While this requires admin access (same as GHSA-4484-8v2f-5748, which was rated moderate), it allows arbitrary PHP function execution and information disclosure via phpinfo.
craftcms/cms >= 5.5.0, <= 5.9.13Upgrade to a patched release:
craftcms/cms 5.9.14Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55794HighCraft CMS: Potential authenticated Remote Code Execution via referrer redirect
GHSA-xxpx-f366-4xpqMediumCraft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
GHSA-wg23-69c2-gjc8CriticalCraft CMS: Passkey login accepts replayed WebAuthn assertions
GHSA-p8x7-9vfw-p7vcHighCraft CMS: Arbitrary user password reset leading to administrator account takeover
GHSA-2rp4-x2j7-qmccMediumCraft CMS: Stored XSS in the control panel via unescaped draft name
GHSA-7hxc-f267-h5q7LowCraft CMS: Incorrect path validation could potentially lead to path traversal