Intel

AIKIDO-2026-10118

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-5fvc-7894-ghp4 Published Feb 5, 2026

80

High Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.16.19
Fixed in 4.17.0
5.0.0 - 5.8.23
Fixed in 5.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain multiple undisclosed server-side request forgery (SSRF) and server-side template injection (SSTI) vulnerabilities. These issues may allow attackers to influence server-side request handling or template rendering logic in unexpected ways, potentially leading to unauthorized network access, information disclosure, or further impact depending on application configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.

How to fix this

Upgrade the craftcms/cms library to the patch version.