Vulnerability GHSA-98vj-mm79-v77r

Medium Risk
MEDIUM RISK
CVSS Score: 6.6
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
10 months ago
November 25, 2025 at 08:43 PM UTC
Contao is vulnerable to remote code execution in template closures
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4

Summary

Contao is vulnerable to remote code execution in template closures

Details

Impact

Backend users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters.

Patches

Update to Contao 4.13.57, 5.3.42 or 5.6.5

Workarounds

Manually patch the Contao\Template::once() method.

Resources

https://contao.org/en/security-advisories/remote-code-execution-in-template-closures

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Low Risk
3 days ago
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Low Risk
10 months ago
Contao is vulnerable to cross-site scripting in templates
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-68q5-78xp-cwwc
4.0.0 - 4.0.4 and 4.1.0 - 4.1.3 and 4.2.0 - 4.2.5 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.56 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.41 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.4 GHSA-68q5-78xp-cwwc
Medium Risk
1 year ago
Contao does not properly manage privileges for page and article fields
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 GHSA-qqfq-7cpp-hcqj
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
10 months ago
November 25, 2025 at 08:43 PM UTC
Fixed (5.3.42)
10 months ago
November 25, 2025 at 03:32 PM UTC
Fixed (4.13.57)
10 months ago
November 25, 2025 at 03:43 PM UTC
Fixed (5.6.5)
10 months ago
November 25, 2025 at 04:01 PM UTC
Last Modified
10 months ago
November 27, 2025 at 09:16 AM UTC