{"id":"CVE-2026-41129","aliases":["GHSA-3m9m-24vh-39wx"],"url":"https://o3.security/vulnerability/CVE-2026-41129","summary":"Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations","details":"Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: \"Edit assets in the <VolumeName> volume\" and \"Create assets in the <VolumeName> volume.\" Versions 4.17.9 and 5.9.15 patch the issue.","published":"2026-04-21T23:34:56.801Z","modified":"2026-08-12T03:51:19.396594122Z","cvss":null,"epss":{"score":0.00275,"percentile":0.19731,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.9.15"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.17.9"}],"fix":{"url":"https://github.com/craftcms/cms/commit/d20aecfaa0eae076c4154be3b17e1f9fa05ce46f","label":"craftcms/cms@d20aecf"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41129.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-3m9m-24vh-39wx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41129"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/d20aecfaa0eae076c4154be3b17e1f9fa05ce46f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.396594122Z"}}