CVE-2025-68437Medium· 6.8▾ SunlitCraft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL save_<VolumeName>_Asset mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the _file input, specifically its url parameter, allows the server to fetch content from arbitrary remote locations without proper validation. Attackers can exploit this by providing internal IP addresses or cloud metadata endpoints as the url, forcing the server to make requests to these restricted services. The fetched content is then saved as an asset, which can subsequently be accessed and exfiltrated, leading to potential data exposure and infrastructure compromise. This exploitation requires specific GraphQL permissions for asset management within the targeted volume. Users should update to the patched 5.8.21 and 4.16.17 releases to mitigate the issue.
craft_cms >= 3.5.0, < 4.16.17craft_cms >= 5.0.1, < 5.8.21craft_cms = 5.0.0Upgrade past the affected range:
craft_cms 5.8.21Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68454High· 8.8Craft is a platform for creating digital experiences
CVE-2025-68455High· 7.2Craft is a platform for creating digital experiences
CVE-2025-68456Critical· 9.1Craft is a platform for creating digital experiences
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2025-68436Medium· 6.5Craft is a platform for creating digital experiences
CVE-2025-32432Critical· 10.0Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond