CVE-2025-13828 describes a critical vulnerability where a low-privileged user can install and remove arbitrary packages via Composer, even when Composer-based updates are disabled. This allows an attacker to install malicious code, potentially leading to privilege escalation and full compromise of the affected system. With a CVSS score of 9.0 (CRITICAL), the vulnerability has a low attack complexity and requires no user interaction, making it highly exploitable. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mautic | Mautic | <4.4.18, <5.2.9, <6.0.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.