### Summary A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ### Impact An authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. ### Patched Versions This security issue has been addressed in the following releases: * **7.1.2** * **6.0.9** * **5.2.11** For users on Mautic 4.x, this fix is available in: * **4.4.20** via [ELTS](https://mautic.org/extended-long-term-support-elts/) Mautic strongly recommend upgrading to a patched version immediately. ### Workarounds There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (`core:themes:create`) to only highly trusted administrators.
Update mautic/core to 5.2.11; mautic/core to 6.0.9; mautic/core to 7.1.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMautic has Server-Side Template Injection (SSTI) in Theme Templates affects mautic/core (composer), mautic/core (composer), mautic/core (composer), mautic/core (composer). Severity is critical. ### Summary A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ### Impact An authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. ### Patched Versions This security issue has been addressed in the following releases: * **7.1.2** * **6.0.9** * **5.2.11** For users on Mautic 4.x, this fix is available in: * **4.4.20** via [ELTS](https://mautic.org/extended-long-term-support-elts/) Mautic strongly recommend upgrading to a patched version immediately. ### Workarounds There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (`core:themes:create`) to only highly trusted administrators.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Summary A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ### Impact An authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. ### Patched Versions This security issue has been addressed in the following releases: * **7.1.2** * **6.0.9** * **5.2.11** For users on Mautic 4.x, this fix is available in: * **4.4.20** via [ELTS](https://mautic.org/extended-long-term-support-elts/) Mautic strongly recommend upgrading to a patched version immediately. ### Workarounds There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (`core:themes:create`) to only highly trusted administrators.
Update mautic/core to 5.2.11; mautic/core to 6.0.9; mautic/core to 7.1.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMautic has Server-Side Template Injection (SSTI) in Theme Templates affects mautic/core (composer), mautic/core (composer), mautic/core (composer), mautic/core (composer). Severity is critical. ### Summary A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code. ### Impact An authenticated user with theme upload and creation privileges can bypass boundaries to execute arbitrary system commands on the hosting server (Remote Code Execution) or access restricted system files and configuration settings. ### Patched Versions This security issue has been addressed in the following releases: * **7.1.2** * **6.0.9** * **5.2.11** For users on Mautic 4.x, this fix is available in: * **4.4.20** via [ELTS](https://mautic.org/extended-long-term-support-elts/) Mautic strongly recommend upgrading to a patched version immediately. ### Workarounds There are no official workarounds. To mitigate this vulnerability without upgrading, restrict theme upload and creation permissions (`core:themes:create`) to only highly trusted administrators.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| mautic/corecomposer | >=1.3.0,<4.4.13 | Not reported |
|---|---|---|
| mautic/corecomposer | >=5.0.0,<5.2.11 | 5.2.11 |
| mautic/corecomposer | >=6.0.0,<6.0.9 | 6.0.9 |
| mautic/corecomposer | >=7.0.0,<7.1.2 | 7.1.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| mautic/corecomposer | >=1.3.0,<4.4.13 | Not reported |
|---|---|---|
| mautic/corecomposer | >=5.0.0,<5.2.11 | 5.2.11 |
| mautic/corecomposer | >=6.0.0,<6.0.9 | 6.0.9 |
| mautic/corecomposer | >=7.0.0,<7.1.2 | 7.1.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard