CVE-2025-32432
About
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
Rainforest analyst review
Craft CMS carries a remote code execution flaw in a code path related to asset transforms, an additional fix to the earlier CVE-2023-41892. An unauthenticated attacker sends crafted input that Craft ultimately evaluates or writes in a way that leads to code execution on the server, described as a high-impact, low-complexity attack. Reported exploitation paired a leaked or brute-forced security key with the flaw to load a malicious PHP payload, turning a web request into a foothold on the host.
Craft is a PHP CMS running on public web servers for agencies, brands, and publishers, so code execution means control of the site, its database, and often adjacent infrastructure. Exploitation was observed in the wild against internet-facing instances, with attackers deploying file managers and web shells, and it is on CISA's KEV list. Upgrade to 3.9.15, 4.14.15, or 5.6.17. Because the attack leaned on knowledge of the application's security key, rotate that key and other secrets after patching, and hunt for uploaded PHP files, unexpected admin accounts, and anomalous requests to the transform endpoints, since an exposed site may already have been reached.
References
- https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical
- https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical
- https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical
- https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47
- https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3
- https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432
Related CVEs
Frequently asked questions
What is CVE-2025-32432?
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector.
How severe is CVE-2025-32432?
CVE-2025-32432 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2025-32432 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability Low.
Which products are affected by CVE-2025-32432?
Public advisories list the following as affected: craft cms. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-32432?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
