GHSA-5xw2-57jx-pgjp

Suggest an improvement
Source
https://github.com/advisories/GHSA-5xw2-57jx-pgjp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-5xw2-57jx-pgjp/GHSA-5xw2-57jx-pgjp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5xw2-57jx-pgjp
Aliases
  • CVE-2025-13827
Published
2025-12-02T21:11:33Z
Modified
2025-12-02T21:37:53.759277Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
GrapesJsBuilder File Upload allows all file uploads
Details

Summary

Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted.

Impact

If the media folder is not restricted from running files this can lead to a remote code execution.

Database specific
{
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-434"
    ],
    "nvd_published_at": "2025-12-02T17:16:03Z",
    "github_reviewed_at": "2025-12-02T21:11:33Z"
}
References

Affected packages

Packagist / mautic/grapes-js-builder-bundle

Package

Name
mautic/grapes-js-builder-bundle
Purl
pkg:composer/mautic/grapes-js-builder-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.4.18

Affected versions

4.*

4.0.0
4.0.1
4.0.2
4.1
4.1.1
4.1.2
4.2.0-rc
4.2.0-rc1
4.2.0
4.2.1
4.2.2
4.3.0-beta
4.3.0-rc
4.3.0
4.3.1
4.4.0-beta
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.4.10
4.4.11
4.4.12
4.4.13

Packagist / mautic/grapes-js-builder-bundle

Package

Name
mautic/grapes-js-builder-bundle
Purl
pkg:composer/mautic/grapes-js-builder-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.2.9

Affected versions

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.2.0
5.2.1
5.2.2
5.2.3
5.2.4
5.2.5
5.2.6
5.2.7
5.2.8

Packagist / mautic/grapes-js-builder-bundle

Package

Name
mautic/grapes-js-builder-bundle
Purl
pkg:composer/mautic/grapes-js-builder-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.0.7

Affected versions

6.*

6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0.5
6.0.6