CVE-2025-68436: Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests.
Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Resources:
https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9
https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9
Other sources
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68436?
CVE-2025-68436 is considered a high-severity vulnerability that can expose sensitive assets.
How do I fix CVE-2025-68436?
To fix CVE-2025-68436, users must update their Craft installation to version 5.8.21 or 4.16.17.
Who is affected by CVE-2025-68436?
Authenticated users on a Craft installation are potentially affected by CVE-2025-68436.
What type of attack is CVE-2025-68436 associated with?
CVE-2025-68436 is associated with potential asset exposure through maliciously crafted requests.
What versions of CraftCMS are vulnerable to CVE-2025-68436?
Versions of CraftCMS between 4.0.0-RC1 and 4.16.16, and between 5.0.0-RC1 and 5.8.20 are vulnerable to CVE-2025-68436.