solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF)
82
High Risk
Freeform's GraphQL submission mutation accepts a remote URL for a File Upload field and fetches it on the server without restricting the destination or checking the resolved IP address. A GraphQL client with permission to submit the affected form can make the server request internal services or cloud metadata endpoints, and can supply a filename whose extension bypasses the field's allowed extension configuration. The fix validates the URL scheme, resolves it to a public IP address, pins the outbound connection to that address, disables redirects, checks the file extension before and after filename normalization, and caps the downloaded size.
You are affected if you are using a version that falls within the vulnerable range and your GraphQL schema grants permission to submit a form containing a File Upload field that accepts a remote URL.
solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.0.0 - 5.16.1.
Upgrade the solspace/craft-freeform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.