CVE-2025-34086
Last modified
CVE-2025-34086 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of the user profile, which is rendered unsanitized in backend templates. EPSS estimates a 2.15% chance of exploitation in the next 30 days.
Description
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of the user profile, which is rendered unsanitized in backend templates. The attacker can then list and rename cached session files via the /async/browse/cache/.sessions and /async/folder/rename endpoints. By renaming a .session file to a path under the publicly accessible /files/ directory with a .php extension, the attacker can turn the injected code into an executable web shell. Finally, the attacker triggers the payload via a crafted HTTP GET request to the rogue file. NOTE: The vendor announced that Bolt 3 reached end-of-life after 31 December 2021.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Boltcms | Bolt | <= 3.7.0 |
References
- https://github.com/bolt/boltProduct
- https://github.com/bolt/bolt/releases/tag/3.7.1Release Notes
- https://www.exploit-db.com/exploits/48296Exploit, VDB Entry
- https://www.rapid7.com/db/modules/exploit/unix/webapp/bolt_authenticated_rce/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-34086?
How severe is CVE-2025-34086?
How do I fix CVE-2025-34086?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-34080The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable…6.1
- CVE-2025-34081The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP…7.5
- CVE-2025-34082A command injection vulnerability exists in IGEL OS versions…9.3
- CVE-2025-34083Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34084Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34085Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-34087An authenticated command injection vulnerability exists in P…8.8
- CVE-2025-34088An authenticated remote code execution vulnerability exists …8.8
- CVE-2025-34089An unauthenticated remote code execution vulnerability exist…9.3
- CVE-2025-3409A vulnerability classified as critical has been found in Not…8.8
- CVE-2025-34090Rejected reason: Neither filed by Chrome nor a valid securit…
- CVE-2025-34091Rejected reason: Neither filed by Chrome nor a valid securit…
Are you affected by CVE-2025-34086?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
