CVE-2025-6384

Source
https://cve.org/CVERecord?id=CVE-2025-6384
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6384.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-6384
Aliases
Published
2025-06-19T21:15:27Z
Modified
2026-08-27T09:37:42Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.

By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution).

This issue affects CrafterCMS: from 4.0.0 through 4.2.2.

References

Affected packages

Git / github.com/craftersoftware/craftercms

Affected ranges

Type
GIT
Repo
https://github.com/craftersoftware/craftercms
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.1
v4.1.2
v4.2.0
v4.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6384.json"