Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. craftcms/cms
  4. ›
  5. CVE-2025-68437

CVE-2025-68437: Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation

January 5, 2026

The Craft CMS GraphQL save_<VolumeName>_Asset mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the _file input, specifically its url parameter, allows the server to fetch content from arbitrary remote locations without proper validation. Attackers can exploit this by providing internal IP addresses or cloud metadata endpoints as the url, forcing the server to make requests to these restricted services. The fetched content is then saved as an asset, which can subsequently be accessed and exfiltrated, leading to potential data exposure and infrastructure compromise. This exploitation requires specific GraphQL permissions for asset management within the targeted volume.

Users should update to the patched 5.8.21 and 4.16.17 releases to mitigate the issue.References:

https://github.com/craftcms/cms/commit/013db636fdb38f3ce5657fd196b6d952f98ebc52

https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md

References

  • github.com/advisories/GHSA-x27p-wfqw-hfcc
  • github.com/craftcms/cms
  • github.com/craftcms/cms/blob/5.x/CHANGELOG.md
  • github.com/craftcms/cms/commit/013db636fdb38f3ce5657fd196b6d952f98ebc52
  • github.com/craftcms/cms/security/advisories/GHSA-x27p-wfqw-hfcc
  • nvd.nist.gov/vuln/detail/CVE-2025-68437

Code Behaviors & Features

Detect and mitigate CVE-2025-68437 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.5.0 before 4.16.17, all versions starting from 5.0.0-RC1 before 5.8.21

Fixed versions

  • 5.8.21
  • 4.16.17

Solution

Upgrade to versions 4.16.17, 5.8.21 or above.

Impact 4.9 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

packagist/craftcms/cms/CVE-2025-68437.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 08 Jan 2026 12:19:29 +0000.