CVE-2025-6384
CVE-2025-6384 is a critical-severity vulnerability in Craftercms with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-913.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v4: 7.3
- EPSS exploit prediction: 1% (61st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-18697
- Weakness: CWE-913
- Affected product: Craftercms
- Published:
- Last modified:
Description
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
Frequently asked questions
- What is CVE-2025-6384?
- Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution). This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
- How severe is CVE-2025-6384?
- CVE-2025-6384 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-6384 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (61st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-6384?
- CVE-2025-6384 affects Craftercms. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-6384?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-6384 have an EU (EUVD) identifier?
- Yes. CVE-2025-6384 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-18697.
- When was CVE-2025-6384 published?
- CVE-2025-6384 was published on 2025-06-19 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*
More vulnerabilities in Craftercms
- CVE-2025-0502 — Critical (CVSS 9.1): Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux,…
- CVE-2023-4136 — High (CVSS 7.4): Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine…
- CVE-2023-33194 — Low (CVSS 3.7): Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output…
All CVEs affecting Craftercms →
Other CWE-913 vulnerabilities
- CVE-2026-92955 — Critical (CVSS 10.0): vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__…
- CVE-2026-92953 — Critical (CVSS 10.0): vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox…
- CVE-2026-92946 — Critical (CVSS 10.0): vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit…
- CVE-2026-47208 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout…
- CVE-2026-47137 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903)…
- CVE-2026-47131 — Critical (CVSS 10.0): vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining…