Critical severityGHSA Advisory· Published Dec 2, 2025· Updated Apr 15, 2026
CVE-2025-13828
CVE-2025-13828
Description
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mautic/corePackagist | >= 4.0.0, < 4.4.18 | 4.4.18 |
mautic/corePackagist | >= 5.0.0, < 5.2.9 | 5.2.9 |
mautic/corePackagist | >= 6.0.0, < 6.0.7 | 6.0.7 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.