GrapesJsBuilder File Upload allows all file uploads
Vulnerability Description
Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13827
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Jason Woods (driskell)
- Patryk Gruszka (patrykgruszka)
- Jan Linhart (escopecz)
- Jason Woods (driskell)
More from Mautic
View All →Affected Vendor
Mautic
View all reports →