Intel

AIKIDO-2026-833597

solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-5r6p-f282-rc8g Published 2 days ago

82

High Risk

This Affects:

PHPsolspace/craft-freeform
5.0.0 - 5.16.1
Fixed in 5.16.2
Are you affected? Scan for Free

TL;DR

Freeform's GraphQL submission mutation accepts a remote URL for a File Upload field and fetches it on the server without restricting the destination or checking the resolved IP address. A GraphQL client with permission to submit the affected form can make the server request internal services or cloud metadata endpoints, and can supply a filename whose extension bypasses the field's allowed extension configuration. The fix validates the URL scheme, resolves it to a public IP address, pins the outbound connection to that address, disables redirects, checks the file extension before and after filename normalization, and caps the downloaded size.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your GraphQL schema grants permission to submit a form containing a File Upload field that accepts a remote URL.

Background info

solspace/craft-freeform is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.0.0 - 5.16.1.

How to fix this

Upgrade the solspace/craft-freeform library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform