CVE-2024-58136criticalunder attackCWE-424

CVE-2024-58136: critical vulnerability in yiiframework Yii

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9epss 88%
from disclosure to weapon
Published on NVDApr 10
CISA KEV+22d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2025-05-23

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Yii 2 framework versions before 2.0.52 have a flaw that allows attackers to exploit how behaviors are attached using a __class array key, enabling unauthorized code execution. This is a regression from a previous fix and was actively exploited in the wild.

Technical detail

CWE-424 (Unrestricted Upload of File with Dangerous Type) relates to unsafe object instantiation via the __class parameter in behavior attachment. The vulnerability allows remote code execution when untrusted input is processed during behavior configuration, with no authentication required. Exploitation involves crafting malicious payloads in behavior definitions that instantiate arbitrary classes, a regression from CVE-2024-4990.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
yiiframework · Yii