LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 2, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 23, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-58136 to its Known Exploited Vulnerabilities catalog on May 2, 2025, with a federal patch deadline of May 23, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement…

CVE-2024-58136 is an improper protection of alternate path vulnerability in the Yii Framework. According to CISA, it may allow a remote attacker to execute arbitrary code. The issue can also affect other products that implement Yii, including but not limited to Craft CMS (as represented by CVE-2025-32432). IT and security teams should treat this as a high-priority review item for any Yii-based applications because remote code execution can lead to full system compromise.

Public detail is limited to the CWE-424 classification and the CISA summary. Confirm exact impact, affected releases, and remediation steps against the vendor advisory before acting.

How it works

CWE-424 covers cases where software fails to properly protect alternate paths that can reach the same resource or function as a primary, better-protected path. In this class of flaw an attacker can bypass intended access controls or validation by using a less-restricted route, parameter, or URL pattern.

For Yii Framework the CISA summary states that the improper protection may permit remote arbitrary code execution. No further exploit mechanics, payloads, or preconditions are provided in the available facts. Attackers would typically probe for alternate request paths that the framework handles without the same safeguards applied to the main path. Specifics of how the bypass is achieved must be confirmed against the vendor advisory; do not assume particular request formats or authentication requirements.

Am I affected? How to find it in your systems

Yii is a PHP web application framework commonly used for custom applications and also embedded in other products such as Craft CMS. Inventory any PHP applications, content-management systems, or third-party packages that declare Yii as a dependency.

Because the vulnerability can affect products that merely implement Yii, expand the search beyond pure Yii applications.

How to remediate

Apply the vendor-supplied update or mitigation instructions for Yii Framework as the primary remediation. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Confirm the exact package name, version range, and update procedure against the vendor advisory; the facts do not supply those details.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to an alternate-path remote-code-execution risk.

These measures lower risk but do not eliminate it; schedule the permanent patch as soon as possible. Ransomware use of this CVE is not documented in the available facts.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to data breaches, credential theft, or further lateral movement. If you determine that a vulnerable Yii-based system was reachable and unpatched, treat the incident as a potential compromise: isolate the host, preserve logs, and begin forensic review. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether any associated credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedYiiframework · Yii
WeaknessCWE-424
Added to CISA KEVMay 2, 2025
Federal patch deadlineMay 23, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities