CVE-2025-13828 PUBLISHED

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

Assigner: Mautic
Reserved: 01.12.2025 Published: 02.12.2025 Updated: 02.12.2025

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9

Product Status

Vendor Mautic
Product Mautic
Versions Default: unaffected
  • Version <4.4.18, <5.2.9, <6.0.7 is affected

Credits

  • Jason Woods (driskell) finder
  • Jason Woods (driskell) remediation developer
  • Jan Linhart (escopecz) remediation reviewer
  • Patryk Gruszka (patrykgruszka) remediation reviewer

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-233 Privilege Escalation