Back

MEDIUM

Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Published Apr 21, 2026

Description

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in the <VolumeName> volume." Versions 4.17.9 and 5.9.15 patch the issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated Apr 22, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-3M9M-24VH-39WX