Description 攻击者可构造恶意请求利用generate-transform端点触发反序列化,执行任意代码控制服务器,未经身份验证的攻击者可以通过该漏洞在目标服务器上注入恶意代码,最终获取服务器权限。
References https://nvd.nist.gov/vuln/detail/CVE-2025-32432 https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432 https://github.com/bambooqj/CVE-2025-32432 https://cve.imfht.com/detail/CVE-2025-32432 https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/ https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 https://www.rapid7.com/db/modules/exploit/linux/http/craftcms_preauth_rce_cve_2025_32432/ https://cn-sec.com/archives/4030053.html https://avd.aliyun.com/detail?id=AVD-2025-32432 https://blog.csdn.net/m0_46699477/article/details/147567097
Related VulnerabilitiesPoCcraftcms-debug-exposure: CraftCMS Debug Methods ExposedPoCcraftcms-install-exposure: Craft CMS Installation Wizard ExposurePoCcraftcms-log-disclosure: Craft CMS - Log File DisclosurePoCCVE-2021-41749: CraftCMS SEOmatic - Server-Side Template InjectionPoCCVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code ExecutionPoCCVE-2025-32432: CraftCMS - Remote Code ExecutionCraft CMS /index.php 代码执行漏洞(CVE-2025-32432)CraftCMS ConditionsController.php 代码执行CraftCMS /ConditionsController.php 代码执行漏洞(CVE-2023-41892)CraftCMS SEOmatic 模板注入漏洞(CVE-2021-41749)