
CraftCMS में कंट्रोल पैनल में रिलेशनल कंडीशनल्स के माध्यम से एक RCE भेद्यता है
CVE-2026-31857, Craft CMS relational condition rules में एक remote code execution समस्या है। BaseElementSelectConditionRule::getElementIds() उपयोगकर्ता-नियंत्रित इनपुट को एक unsandboxed Twig template के रूप में render करता है। एक authenticated Control Panel उपयोगकर्ता element listing endpoint के माध्यम से एक crafted condition सबमिट कर सकता है और सर्वर पर commands execute कर सकता है। Administrator privileges की आवश्यकता नहीं है।
Craft CMS 4.0.0-beta.1 से 4.17.3 तक और 5.0.0-RC1 से 5.9.8 तक प्रभावित हैं। यह PoC Craft 5 element-index request shape का उपयोग करता है।
केवल standard library के साथ Python 3 आवश्यक है। base URL और एक Control Panel username प्रदान करें; script password के लिए prompt करेगा:
python3 poc.py https://craft.example editor
cmd> पर commands दर्ज करें, या quit करने के लिए exit दर्ज करें। वर्तमान working directory commands के बीच बनी रहती है। एक long-running command शुरू करने के लिए, इसे & के साथ समाप्त करें; इसका input और output HTTP request से detached हो जाते हैं और इसका output discard कर दिया जाता है। response header के माध्यम से लौटाया गया command output अंतिम 1200 bytes तक सीमित है।