Crafter CMS Crafter Studio Groovy Sandbox Bypass Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Crafter CMS's Crafter Studio, specifically in versions 4.0 prior to 4.5.0. This vulnerability arises from an improper control of dynamically-managed code resources, allowing authenticated developers to execute operating system commands by bypassing sandbox restrictions in the Groovy environment.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where Crafter CMS is running.

Added: Feb 2, 2026, 5:19 PM
Updated: Feb 2, 2026, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.