CVE 9 CRITICAL

Mautic user without privileged access to the Marketplace can install and uninstall composer packages_CVE-2025-13828

9 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

AI Analysis

A low-privileged user can install malicious code to obtain higher privileges by installing and removing arbitrary packages via composer.

Basic Information

ID CVE-2025-13828
Source Mautic
Published Dec 2, 2025 at 16:54
Modified Dec 2, 2025 at 17:12

Affected Product

Vendor Mautic
Product Mautic
Version <4.4.18, <5.2.9, <6.0.7
Affected Versions Mautic Mautic <4.4.18, <5.2.9, <6.0.7

CWE Classification

AI Assessment

AI Score 9 / 10
AI Severity Critical
Vendor Mautic
Product Mautic
Version <4.4.18, <5.2.9, <6.0.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.