Code Injection in Craft CMS - #VU145005
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in field-layout hydration when processing a field-layout tab whose element value is posted as a JSON string. A remote user can submit crafted field-layout element data with behavior or event-handler keys to execute arbitrary code.
No administrative or special permission is required, and exploitation is reachable by any authenticated control-panel user.