Craft Platform Vulnerability in Asset Management Functionality
CVE-2026-25494
6.9MEDIUM
What is CVE-2026-25494?
In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a vulnerability exists in the saveAsset GraphQL mutation where the function filter_var(..., FILTER_VALIDATE_IP) fails to recognize alternate IP address notations such as hexadecimal and mixed formats. This oversight permits unauthorized access to cloud metadata services, allowing attackers to circumvent the standard IP blocklist. The issue has been resolved in subsequent releases 4.16.18 and 5.8.22.
Affected Version(s)
cms >= 5.0.0-RC1, < 5.8.22
