CVE-2024-56145 enables unauthenticated remote code execution in Craft CMS when PHP's register_argc_argv setting is enabled. Craft CMS bootstrap code accepted CLI-style options from the web-populated $_SERVER['argv'] array, allowing query-string input to override application paths, including the templates directory. The affected condition was present in Craft CMS's official Docker configuration.
An attacker can redirect template resolution to an attacker-controlled FTP server and leverage PHP's FTP stream wrapper to satisfy file-existence checks before Craft CMS downloads and renders a malicious Twig template. Although Twig blocked several direct dangerous callbacks, the published technique bypassed those restrictions through call_user_func used by the sort filter. Craft CMS fixed the flaw in versions 5.5.2 and 4.13.2 and later; organizations unable to upgrade should disable register_argc_argv and review exposed Craft deployments for suspicious template-path overrides.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
HITCON CTF 2018 featured the One Line PHP Challenge, which used PHP session upload-progress handling, a race condition, stream-filter Base64 decoding, and a local file inclusion primitive to achieve code execution. Three of 1,816 teams solved the challenge.
Craft CMS fixed the unauthenticated RCE issue caused by processing web-populated $_SERVER['argv'] values as CLI options. Versions 5.5.2+ and 4.13.2+ are protected; installations unable to upgrade can mitigate the issue by disabling register_argc_argv.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.