Intel

AIKIDO-2026-10118

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-5fvc-7894-ghp4

80

High Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.16.19
Fixed in 4.17.0
5.0.0 - 5.8.23
Fixed in 5.9.0

TL;DR

Affected versions of this package contain multiple undisclosed server-side request forgery (SSRF) and server-side template injection (SSTI) vulnerabilities. These issues may allow attackers to influence server-side request handling or template rendering logic in unexpected ways, potentially leading to unauthorized network access, information disclosure, or further impact depending on application configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.

How to fix this

Upgrade the craftcms/cms library to the patch version.