Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-25125— October CMS: Environment Variable Exfiltration via INI Parser Interpolation

CVSS 4.9 · Medium EPSS 0.01% · P2
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-25125

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
Source: NVD (National Vulnerability Database)
Vulnerability Description
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access could inject patterns such as ${APP_KEY} or ${DB_PASSWORD} into CMS page settings fields, causing sensitive environment variables to be resolved, stored in the template, and returned to the attacker when the page was reopened. This could enable exfiltration of credentials and secrets (database passwords, AWS keys, application keys), potentially leading to further attacks such as database access or cookie forgery. The vulnerability is only relevant when cms.safe_mode is enabled, as direct PHP injection is already possible otherwise. This issue has been fixed in versions 3.7.14 and 4.1.10. If users are unable to immediately upgrade, they can workaround this issue by restricting Editor tool access to fully trusted administrators only, and ensuring database and cloud service credentials are not accessible from the web server's network.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
October 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
October是October开源的一个内容管理系统 (CMS) 和网络平台。 October 3.7.14之前版本和4.1.10之前版本存在信息泄露漏洞,该漏洞源于INI设置解析器存在服务器端信息泄露,可能导致攻击者注入环境变量模式以泄露敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
octobercmsoctober < 3.7.14 -

II. Public POCs for CVE-2026-25125

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-25125

登录查看更多情报信息。

Same Patch Batch · octobercms · 2026-04-14 · 5 CVEs total

CVE-2026-226924.9 MEDIUMOctober CMS: Twig Sandbox Bypass via Collection Methods
CVE-2026-25133October CMS has Stored XSS via SVG Filter Bypass
CVE-2026-24906October CMS has Stored XSS in its Backend Editor Markup Classes
CVE-2026-24907October CMS has Stored XSS via Event Log Mail Preview

IV. Related Vulnerabilities

V. Comments for CVE-2026-25125

No comments yet


Leave a comment