Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in October CMS - CVE-2026-25125

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in October CMS - CVE-2026-25125

Published: April 14, 2026


Vulnerability identifier: #VU125889
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25125
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in the INI settings parser when processing page settings fields containing environment variable interpolation syntax. A remote privileged user can inject crafted ${} patterns into CMS page settings fields to disclose sensitive information.

Only instances with cms.safe_mode enabled are affected.


Affected software

October CMS

How to mitigate CVE-2026-25125

Install security update from vendor's website.

October CMS - update to 4.1.10

External References

Related Security Bulletins