CVE-2026-25125
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
Description
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network.
INFO
Published Date :
April 14, 2026, 9:16 p.m.
Last Modified :
July 25, 2026, 11:10 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Upgrade October CMS to version 3.7.14 or 4.1.10.
- Restrict Editor tool access to trusted administrators.
- Ensure credentials are not web accessible.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-25125.
| URL | Resource |
|---|---|
| https://github.com/octobercms/october/security/advisories/GHSA-g6v3-wv4j-x9hg | Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-25125 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-25125
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-25125 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-25125 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 25, 2026
Action Type Old Value New Value Added Translation Title: October CMS de Octobercms, Description: October es un Sistema de Gestión de Contenidos (CMS) y plataforma web. Las versiones anteriores a la 3.7.14 y 4.1.10 contienen una vulnerabilidad de revelación de información del lado del servidor en el analizador de configuraciones INI. Debido a que la función parse_ini_string() de PHP soporta la sintaxis ${} para la interpolación de variables de entorno, los atacantes con acceso de Editor podrían inyectar patrones como ${APP_KEY} o ${DB_PASSWORD} en los campos de configuración de las páginas del CMS, haciendo que las variables de entorno sensibles se resolvieran, se almacenaran en la plantilla y se devolvieran al atacante cuando la página se volvía a abrir. Esto podría permitir la exfiltración de credenciales y secretos (contraseñas de base de datos, claves de AWS, claves de aplicación), lo que podría conducir a ataques adicionales como el acceso a la base de datos o la falsificación de cookies. La vulnerabilidad solo es relevante cuando cms.safe_mode está habilitado, ya que la inyección directa de PHP ya es posible de otra manera. Este problema ha sido solucionado en las versiones 3.7.14 y 4.1.10. Si los usuarios no pueden actualizar de inmediato, pueden solucionar este problema restringiendo el acceso a la herramienta de Editor solo a administradores de plena confianza y asegurándose de que las credenciales de la base de datos y los servicios en la nube no sean accesibles desde la red del servidor web. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'octobercms', 'product': 'october', 'versions': [{'status': 'affected', 'version': '< 3.7.14'}, {'status': 'affected', 'version': '>= 4.0.0, < 4.1.10'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-25125', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-04-15T14:24:59.493377Z'} -
Initial Analysis by [email protected]
Apr. 22, 2026
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* versions up to (excluding) 3.7.14 *cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.1.10 Added Reference Type GitHub, Inc.: https://github.com/octobercms/october/security/advisories/GHSA-g6v3-wv4j-x9hg Types: Vendor Advisory -
New CVE Received by [email protected]
Apr. 14, 2026
Action Type Old Value New Value Added Description October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network. Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Added CWE CWE-94 Added CWE CWE-200 Added Reference https://github.com/octobercms/october/security/advisories/GHSA-g6v3-wv4j-x9hg