craftcms/feed-me is vulnerable to Server-Side Request Forgery (SSRF)
81
High Risk
The downloadFile() helper in AssetHelper.php fetches a Feed Me asset source value and passes the bytes to Craft's asset storage without checking that the value stays inside the web root or points to a safe public host. A user who can configure or trigger an asset import can set the source to a local filesystem path outside the upload volume or to an internal URL such as a loopback or private network address, so the plugin reads that resource and stores it as a Craft asset, leading to arbitrary local file read and server-side request forgery against internal services. The fix validates remote hosts against reserved and private IP ranges, pins the resolved address with CURLOPT_RESOLVE to prevent DNS rebinding, and blocks dotfiles and restricted directories in local paths.
You are affected if you are using a version that falls within the vulnerable range and you allow users who are not fully trusted to configure or trigger Feed Me asset imports.
craftcms/feed-me is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.1.17 - 6.14.0.
Upgrade the craftcms/feed-me library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.