CVE-2026-31857 is an authenticated remote code execution vulnerability in Craft CMS versions before 4.17.4 and 5.9.9. In the conditions system, BaseElementSelectConditionRule::getElementIds() processes attacker-controlled string input with renderObjectTemplate(), which renders Twig templates without sandboxing and with escaping disabled. A crafted relational condition submitted to standard Control Panel element-listing functionality can therefore cause attacker-supplied Twig expressions to be evaluated in an unsafe context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository contains a README and a standalone Python 3 proof of concept, poc.py, for CVE-2026-31857. The script uses only Python standard-library modules, maintains cookies with urllib, obtains a CSRF token, authenticates a supplied Craft Control Panel user, and verifies the resulting session. It then provides an interactive command prompt. Each command is embedded in a crafted RelatedToConditionRule elementIds value within an element-indexes/count-elements request. The injected Twig calls system via the map filter, enabling server-side shell execution. Shell output and the resolved working directory are base64 encoded and returned through an attacker-defined X-RET-Out HTTP response header; output is limited to the trailing 1,200 bytes. The PoC also detects a trailing single ampersand and wraps such commands with nohup and setsid to execute them detached from the request. It is an operational authenticated RCE exploit rather than merely a vulnerability scanner or detection script.
This three-file repository contains a standalone Python 3 exploit, a README, and a minimal dependency list. CVE-2026-31857.py uses requests.Session to preserve authentication cookies, retrieves CSRF tokens from the Craft login page and authenticated dashboard, then logs in through Craft's users/login action with operator-supplied credentials. It submits a crafted JSON request to the element-indexes/count-elements action. The malicious condition embeds a Twig expression in the RelatedToConditionRule elementIds value; the expression invokes Twig's system filter to execute an OS command. The implemented command is a Bash reverse shell to the attacker IP and port passed on the command line. A request timeout is treated as likely payload execution. The README identifies affected Craft CMS 4.x and 5.x release ranges and documents listener setup and invocation. This is an authenticated RCE exploit, not merely a vulnerability check; it contains a basic fixed-form reverse-shell payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously fixed Craft CMS vulnerability referenced as background because its remediation introduced or relates to the input channel involved in the newly described issue.
A prior Craft CMS vulnerability referenced as having been patched through sandboxed Twig templating; this advisory identifies a separate environment-variable disclosure weakness that bypasses the intended protection.
Remote Code Execution (RCE) in Craft CMS conditions system due to user-controlled input being rendered via an unsandboxed Twig rendering function with escaping disabled, allowing authenticated Control Panel users (including non-admin roles) to execute code.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.