CVE-2026-25493 | Craft CMS up to 4.16.17/5.8.21 GraphQL Mutation saveAsset server-side request forgery (GHSA-8jr8-7hr4-vhfx)
A vulnerability was found in Craft CMS up to 4.16.17/5.8.21 and classified as critical. This affects the function saveAsset of the component GraphQL Mutation Handler. Executing a manipulation can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-25493. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.