VYPR
Critical severityGHSA Advisory· Published Dec 2, 2025· Updated Apr 15, 2026

CVE-2025-13828

CVE-2025-13828

Description

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.

ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mautic/corePackagist
>= 4.0.0, < 4.4.184.4.18
mautic/corePackagist
>= 5.0.0, < 5.2.95.2.9
mautic/corePackagist
>= 6.0.0, < 6.0.76.0.7

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.