GHSA-8v7h-cpc2-r8jp · Severity: high · Ecosystem: composer — October CMS upload process vulnerable to RCE via Race Condition
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.
Conclusion & alert: CVE-2022-24800 is rated Moderate Risk (56.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-07-09 | 1.12% | 1.36% | +0.24% |
| 2 | 2026-06-15 | 2.93% | 1.12% | -1.80% |
| 3 | 2025-07-21 | — | 2.93% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-8v7h-cpc2-r8jp · Severity: high · Ecosystem: composer — October CMS upload process vulnerable to RCE via Race Condition
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| octobercms | october | < 1.0.476 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| octobercms | october | >= 1.1.0, < 1.1.12 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| octobercms | october | >= 2.0.0, < 2.2.15 | cpe:2.3:a:octobercms:october:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/octobercms/library/commit/fe569f3babf3f593be2b1e0a4ae0283506127a83 | Patch Third Party Advisory |
| https://github.com/octobercms/october/security/advisories/GHSA-8v7h-cpc2-r8jp | Patch Third Party Advisory |