Code Injection in Craft CMS - #VU134678
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of user-controlled input in entry saving redirect handling when processing a user-controlled Referer header. A remote user can supply a specially crafted Referer header to execute arbitrary code.
Exploitation requires control panel access and permission to edit an entry.