« Volver al listado

CVE-2026-25633

Estado: AnalizadaMedia (4.3)—

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-25633",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-25633",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-12T21:19:30.676025Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "statamic",
          "product": "cms",
          "versions": [
            {
              "status": "affected",
              "version": "< 5.73.6"
            },
            {
              "status": "affected",
              "version": ">= 6.0.0-alpha.1, < 6.2.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-11T21:16:18.910",
  "references": [
    {
      "url": "https://github.com/statamic/cms/commit/5a6f47246edf3a0c453727ffecbfa14333a6bc8a",
      "tags": [
        "Patch",
        "Product"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/statamic/cms/releases/tag/v5.73.6",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/statamic/cms/releases/tag/v6.2.5",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/statamic/cms/security/advisories/GHSA-gwmx-9gcj-332h",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5."
    },
    {
      "lang": "es",
      "value": "Statamic es un CMS impulsado por Laravel + Git diseñado para construir sitios web. Antes de las versiones 5.73.6 y 6.2.5, los usuarios sin permiso para ver activos pueden descargarlos y ver sus metadatos. Los usuarios que no han iniciado sesión y los usuarios sin permiso para acceder al panel de control no pueden aprovecharse de esto. Esto ha sido corregido en las versiones 5.73.6 y 6.2.5."
    }
  ],
  "lastModified": "2026-06-17T10:24:59.090",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88DCC3F4-B944-450D-BE1D-34F2D8ACBE89",
              "versionEndExcluding": "5.73.6"
            },
            {
              "criteria": "cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C94BE13-7888-4AB4-ABF0-CCA533C344E6",
              "versionEndExcluding": "6.2.5",
              "versionStartIncluding": "6.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}