MEDIUM
Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
Published Apr 21, 2026
5.5
MEDIUMCVSS 4.0
EPSS 0.40%
Description
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in the <VolumeName> volume." Versions 4.17.9 and 5.9.15 patch the issue.
Affected products
-
- Version >= 4.0.0-RC1, < 4.17.9StatusaffectedConstraints-
- Version >= 5.0.0-RC1, < 5.9.15StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-3m9m-24vh-39wx Advisory
- https://github.com/craftcms/cms/commit/d20aecfaa0eae076c4154be3b17e1f9fa05ce46f x_refsource_MISC
- https://github.com/craftcms/cms/security/advisories/GHSA-3m9m-24vh-39wx x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-41129
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-3m9m-24vh-39wx | Advisory | |
| https://github.com/craftcms/cms/commit/d20aecfaa0eae076c4154be3b17e1f9fa05ce46f | x_refsource_MISC | |
| https://github.com/craftcms/cms/security/advisories/GHSA-3m9m-24vh-39wx | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41129 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 21, 2026
Updated Apr 22, 2026
Reserved Apr 17, 2026
Link CVE-2026-41129
CISA Vulnrichment
GHSA-3M9M-24VH-39WX Updated Apr 22, 2026