CVE-2025-13827 - CVE House
Back to Database
Status published High CVE-2025-13827

GrapesJsBuilder File Upload allows all file uploads

Vulnerability Description

Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13827

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Jason Woods (driskell)
  • Patryk Gruszka (patrykgruszka)
  • Jan Linhart (escopecz)
  • Jason Woods (driskell)

Affected Vendor

Affected Software

Mautic
Vulnerable Versions:
<4.4.18, <5.2.9, <6.0.7

Timeline

Official Publish: December 2nd, 2025
Last Modified: December 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)