Intel

AIKIDO-2026-10085

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-gp2f-7wcm-5fhx Published Jan 26, 2026

55

Medium Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.16.18
Fixed in 4.16.19
5.0.0 - 5.8.22
Fixed in 5.8.23
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to multiple server-side request forgery (SSRF) issues. In the GQL plugin, specially crafted requests can trigger unintended outbound network requests. The patched version introduces stricter IP validation, preventing crafted requests from initiating unintended network connections.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.5.0 - 4.16.18 and 5.0.0 - 5.8.22.

How to fix this

Upgrade the craftcms/cms library to the patch version.