Server-Side Request Forgery (SSRF) in Craft CMS - #VU139969

 

Server-Side Request Forgery (SSRF) in Craft CMS - #VU139969

Published: July 29, 2026


Vulnerability identifier: #VU139969
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform server-side request forgery and disclose internal HTTP response content.

The vulnerability exists due to improper access control in the GraphQL asset mutation when fetching an attacker-supplied URL server-side. A remote user can provide a crafted URL to trigger internal requests and disclose internal HTTP response content.

The issue affects GraphQL tokens scoped only to asset creation, and different error and timing outcomes can expose an oracle for blind internal host and port enumeration.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - addressed in versions 4.18.2, 5.10.6

External References

Related Security Bulletins