github.com
https://github.com/mautic/mautic CVE-2025-13828
CRITICAL
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Record summary
CVE-2025-13828 has a selected CVSS score of 9.0 (critical).
Description
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | <4.4.18, <5.2.9, <6.0.7 | affected |
mautic/coreBrowse Packagist / mautic/core | GitHub Advisory | 4.0.0 to < 4.4.18 · Fixed in 4.4.18 | affected |
| 5.0.0 to < 5.2.9 · Fixed in 5.2.9 | affected | ||
| 6.0.0 to < 6.0.7 · Fixed in 6.0.7 | affected |
References
3github.com
https://github.com/mautic/mautic/security/advisories/GHSA-3fq7-c5m8-g86x nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13828