# CVE-2024-58136

## Summary

- **CVE ID:** CVE-2024-58136
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-424
- **Published:** Apr 10, 2025
- **Last Modified:** Oct 21, 2025

## Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

## Affected Products

- yiiframework — Yii (2)

## References

- [CNA](https://github.com/yiisoft/yii2/pull/20232)
- [CNA](https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709)
- [CNA](https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12)
- [CNA](https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52)
- [CNA](https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52)
- [CISA-ADP](https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 84.61%
- **EPSS Percentile:** 99.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** May 2, 2025
- **Due Date:** May 23, 2025

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._