GHSA-3fq7-c5m8-g86x

Suggest an improvement
Source
https://github.com/advisories/GHSA-3fq7-c5m8-g86x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-3fq7-c5m8-g86x/GHSA-3fq7-c5m8-g86x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3fq7-c5m8-g86x
Aliases
  • CVE-2025-13828
Published
2025-12-02T21:10:39Z
Modified
2025-12-02T21:37:54.594242Z
Severity
  • 9.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Details

Summary

A non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

Impact

A low-privileged user of the platform can install malicious code to obtain higher privileges.

Database specific
{
    "severity": "CRITICAL",
    "nvd_published_at": "2025-12-02T17:16:04Z",
    "github_reviewed_at": "2025-12-02T21:10:39Z",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-284",
        "CWE-862"
    ]
}
References

Affected packages

Packagist / mautic/core

Package

Name
mautic/core
Purl
pkg:composer/mautic/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.4.18

Affected versions

4.*

4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0-rc
4.2.0-rc1
4.2.0
4.2.1
4.2.2
4.3.0-beta
4.3.0-rc
4.3.0
4.3.1
4.4.0-beta
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.4.10
4.4.11
4.4.12
4.4.13

Packagist / mautic/core

Package

Name
mautic/core
Purl
pkg:composer/mautic/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.2.9

Affected versions

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8

Packagist / mautic/core

Package

Name
mautic/core
Purl
pkg:composer/mautic/core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.0.7

Affected versions

6.*

6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6