Server-Side Request Forgery Vulnerability in Craft CMS Versions 4.x and 5.x
CVE-2026-41129
5.5MEDIUM
What is CVE-2026-41129?
Craft CMS, a popular content management system, has a vulnerability that allows for server-side request forgery. Specific versions in the 4.x branch up to 4.17.8 and the 5.x branch up to 5.9.14 are impacted. Exploitation of this vulnerability requires certain permissions to be enabled in the GraphQL schema, specifically 'Edit assets in the volume' and 'Create assets in the volume.' It is crucial for users operating affected versions to upgrade to 4.17.9 or 5.9.15, which address this security issue. For more information, please refer to the advisory and commit provided by Craft CMS.
Affected Version(s)
cms >= 5.0.0-RC1, < 5.9.15 < 5.0.0-RC1, 5.9.15
cms >= 4.0.0-RC1, < 4.17.9 < 4.0.0-RC1, 4.17.9
