Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Package
Affected versions
>= 4.0.0, < 4.4.18
>= 5.0.0, < 5.2.9
>= 6.0.0, < 6.0.7
Patched versions
4.4.18
5.2.9
6.0.7
Description
Published by the National Vulnerability Database
Dec 2, 2025
Published to the GitHub Advisory Database
Dec 2, 2025
Reviewed
Dec 2, 2025
Last updated
Dec 2, 2025
Summary
A non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
Impact
A low-privileged user of the platform can install malicious code to obtain higher privileges.
References