Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
The Yii 2 framework allows dynamic attachment of behaviors to components through array configuration containing a special __class key. Due to a regression introduced after the CVE-2024-4990 fix, the configuration processing mechanism again contains a flaw that allows an attacker to substitute a malicious class. An unauthenticated remote attacker can remotely deliver crafted input, leading to uncontrolled object instantiation and server-side code execution.
An attacker can gain full control over the application server — achieve remote code execution (RCE), access sensitive data, and permanently compromise system integrity and availability.
Yii 2 must be immediately updated to version 2.0.52 or later. The patch is available in the project repository (commit 40fe496) and described in the official vendor advisory at https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52
Yii 2 versions before 2.0.52 (Yiiframework Yii)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HYiiframework Yii
APPYiiframework< 2.0.52
CISA KEV — detailsi
- Vendori
- Yiiframework
- Producti
- Yii
- Added to KEVi
- May 2, 2025
- Remediation deadline (US Federal)i
- May 23, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.
Related vulnerabilities
Yii2: Instantiacja dowolnych klas przez metodę __set() w klasie Component
Path Traversal w Yii2 umożliwiający wykonanie dowolnego pliku PHP
SQL injection w Yii 2 Framework umożliwiający zdalne wykonanie kodu
Zdalne wykonanie kodu LUA w Yii Framework przez rozszerzenie Redis
SQL Injection w Yii 2.x — podatna funkcja findByCondition()