CVE-2026-41129: Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in the <VolumeName> volume." Versions 4.17.9 and 5.9.15 patch the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41129?
CVE-2026-41129 is considered a critical vulnerability due to its potential for Server-Side Request Forgery exploitation.
How do I fix CVE-2026-41129?
To remediate CVE-2026-41129, upgrade Craft CMS to version 4.17.9 or 5.9.15 or later.
What versions of Craft CMS are affected by CVE-2026-41129?
CVE-2026-41129 affects Craft CMS versions 4.x through 4.17.8 and 5.x through 5.9.14.
What type of vulnerability is CVE-2026-41129?
CVE-2026-41129 is a Server-Side Request Forgery (SSRF) vulnerability.
Who is the vendor of the affected software for CVE-2026-41129?
The vendor of the affected software for CVE-2026-41129 is Pixel & Tonic.