Intel

AIKIDO-2026-801685

craftcms/feed-me is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-wq63-9pmc-5mwx Published 2 days ago

81

High Risk

This Affects:

PHPcraftcms/feed-me
3.1.17 - 6.14.0
Fixed in 6.15.0
Are you affected? Scan for Free

TL;DR

The downloadFile() helper in AssetHelper.php fetches a Feed Me asset source value and passes the bytes to Craft's asset storage without checking that the value stays inside the web root or points to a safe public host. A user who can configure or trigger an asset import can set the source to a local filesystem path outside the upload volume or to an internal URL such as a loopback or private network address, so the plugin reads that resource and stores it as a Craft asset, leading to arbitrary local file read and server-side request forgery against internal services. The fix validates remote hosts against reserved and private IP ranges, pins the resolved address with CURLOPT_RESOLVE to prevent DNS rebinding, and blocks dotfiles and restricted directories in local paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you allow users who are not fully trusted to configure or trigger Feed Me asset imports.

Background info

craftcms/feed-me is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.1.17 - 6.14.0.

How to fix this

Upgrade the craftcms/feed-me library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform