Remote Code Execution Vulnerability in Craft CMS (CVE-2025-32432)

ISGroup Cybersecurity

Craft CMS is a widely used content management system for building custom websites. A critical security vulnerability has been identified that allows attackers to take complete control of a vulnerable site remotely. This issue affects several major versions of the platform and poses a high risk to any site that has not applied the latest security updates.

ProductCraft CMS
Date2025-05-02 15:19:41
Information
  • Fix Available
  • Active Exploitation

Technical Summary

CVE-2025-32432 is a critical unauthenticated Remote Code Execution (RCE) vulnerability affecting the following Craft CMS versions:

  • 3.0.0-RC1 to < 3.9.15
  • 4.0.0-RC1 to < 4.14.15
  • 5.0.0-RC1 to < 5.6.17

The issue lies in the handling of user input within the generate-transform endpoint of the Craft CMS administration panel. An attacker can exploit this vulnerability by sending a specially crafted JSON payload in a POST request, using object injection to instantiate internal PHP classes in unintended ways. This results in arbitrary code execution on the server side, without requiring authentication or user interaction.

The vulnerability stems from insecure deserialization logic and is an extension of a previously reported issue (CVE-2023-41892), which has been further addressed with this CVE.

Recommendations

  • Immediately update Craft CMS to one of the following secure versions:
    • 3.9.15
    • 4.14.15
    • 5.6.17

  • Implement security monitoring to detect anomalous POST requests to /admin/actions/assets/generate-transform.
  • Restrict access to the administration panel using an IP whitelist or a VPN if possible.
  • Consider implementing a Web Application Firewall (WAF) to detect or block deserialization attempts.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert