CVE-2026-33157 | Craft CMS up to 5.9.12 cleanseConfig fieldLayouts externally-controlled input to select classes or code
A vulnerability was found in Craft CMS up to 5.9.12. It has been declared as problematic. The affected element is the function cleanseConfig. Such manipulation of the argument fieldLayouts leads to use of externally-controlled input to select classes or code.
This vulnerability is referenced as CVE-2026-33157. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.