Crafter Studio Groovy Sandbox Bypass
High severity
GitHub Reviewed
Published
Jun 19, 2025
to the GitHub Advisory Database
•
Updated Jun 20, 2025
Package
Affected versions
>= 4.0.0, < 4.3.0
Patched versions
4.3.0
Description
Published by the National Vulnerability Database
Jun 19, 2025
Published to the GitHub Advisory Database
Jun 19, 2025
Reviewed
Jun 20, 2025
Last updated
Jun 20, 2025
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass.
By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain RCE (Remote Code Execution).
This issue affects CrafterCMS: from 4.0.0 through 4.2.2.
References