Server-Side Request Forgery (SSRF) in Craft CMS - CVE-2026-41129
Published: June 16, 2026
Craft CMS
Detailed vulnerability description
The vulnerability allows a remote user to access internal services via server-side request forgery.
The vulnerability exists due to server-side request forgery in the GraphQL asset upload mutations when processing user-supplied asset URLs. A remote user can supply a crafted gopher URL to access internal services via server-side request forgery.
Exploitation requires GraphQL schema permissions to edit assets in the volume and create assets in the volume.