← Retour aux CVEs
CVE-2026-25492
MEDIUM6.5
Description
Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP address, bypassing hostname validation. When a non-image file extension such as .txt is allowed, downstream image validation is bypassed, which can allow an authenticated attacker with permission to use save_images_Asset to retrieve sensitive data such as AWS instance metadata credentials from the underlying host. This issue is patched in versions 4.16.18 and 5.8.22.
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie2/9/2026
Derniere modification2/19/2026
Sourcenvd
Observations honeypot0
Produits affectes
craftcms:craft_cms
Faiblesses (CWE)
CWE-918
References
https://github.com/craftcms/cms/commit/e838a221df2ab15cd54248f22fc8355d47df29ff(security-advisories@github.com)
https://github.com/craftcms/cms/releases/tag/5.8.22(security-advisories@github.com)
https://github.com/craftcms/cms/security/advisories/GHSA-96pq-hxpw-rgh8(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.