CVE-2024-58136 — Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Published
2025-04-10T00:00:00.000Z
Last modified
2025-10-21T22:55:21.228Z
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV — Actively Exploited
01What is this vulnerability?
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
02Affected products
| Vendor | Product | Versions |
|---|
| yiiframework | Yii | 2 |
03Active exploitation status
Yes — actively exploited. Added to the CISA KEV catalog on 2025-05-02. Ransomware use: Unknown.
04Recommended remediation
- Patch to a fixed version listed in the vendor advisory (see references below).
- Mitigate with WAF rules, network egress filters, or feature flags where the patch is not yet available.
- Hunt historical logs for exploitation indicators — see Detection signatures below.
05Technical details
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
06Detection signatures
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
Open in Sigma generator →
07Related CVEs
08Timeline
- Published: 2025-04-10T00:00:00.000Z
- Last modified: 2025-10-21T22:55:21.228Z
- Added to CISA KEV: 2025-05-02
- BOD 22-01 due: 2025-05-23
09References
- github.com — https://github.com/yiisoft/yii2/pull/20232
- github.com — https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709
- github.com — https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12
- github.com — https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52
- www.yiiframework.com — https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52
Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →