craftcms/cms is vulnerable to Improper Authorization
50
Medium Risk
Affected versions of this package are vulnerable to permission escalation because certain GraphQL asset mutation logic did not enforce correct ownership checks, allowing a user with privileges to save or create assets to potentially act on volumes they shouldn’t have access to. The referenced commit adds explicit checks to ensure the asset’s volume ID matches the expected volume and requires the appropriate schema action for unauthorized attempts, preventing attackers from exploiting the mutation to escalate privileges or modify resources outside their permitted scope.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Improper Authorization in versions 3.5.0 - 4.16.17 and 5.0.0 - 5.8.21.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant