{"id":"CVE-2026-55791","aliases":["GHSA-c55v-343g-5xff"],"url":"https://o3.security/vulnerability/CVE-2026-55791","summary":"Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs","details":"Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0.","published":"2026-07-01T23:13:58.321Z","modified":"2026-08-12T03:51:43.446918356Z","cvss":null,"epss":{"score":0.00464,"percentile":0.38621,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"5.10"},{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":"4.18"}],"fix":{"url":"https://github.com/craftcms/cms/pull/18559","label":"craftcms/cms#18559"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55791.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-c55v-343g-5xff"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55791"},{"type":"FIX","url":"https://github.com/craftcms/cms/pull/18559"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.446918356Z"}}