Backend users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters.
Update to Contao 4.13.57, 5.3.42 or 5.6.5
Manually patch the Contao\Template::once() method.
https://contao.org/en/security-advisories/remote-code-execution-in-template-closures
{
"nvd_published_at": "2025-11-25T19:15:51Z",
"github_reviewed": true,
"github_reviewed_at": "2025-11-25T20:43:13Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-351"
]
}