CVE-2025-13828EPSS p14.4%
CVE-2025-13828CVE-2025-13828
Description
SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked.
ImpactA low-privileged user of the platform can install malicious code to obtain higher privileges.
Scoring
| EPSS | 0.25% probability of exploitation · percentile 14.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-03 |