{"id":"CVE-2025-68436","aliases":["GHSA-53vf-c43h-j2x9"],"url":"https://o3.security/vulnerability/CVE-2025-68436","summary":"Craft CMS vulnerable to potential information disclosure via unchecked asset relocation","details":"Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.","published":"2026-01-05T21:46:01.734Z","modified":"2026-08-08T03:48:16.431907124Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.8.21"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.16.17"}],"fix":{"url":"https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9","label":"craftcms/cms@4bcb0db"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68436.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-53vf-c43h-j2x9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68436"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:16.431907124Z"}}