CVE-2026-25498 | Craft CMS up to 4.16.17/5.8.21 src/services/Fields.php assembleLayoutFromPost externally-controlled input to select classes or code (GHSA-7jx7-3846-m7w7)
A vulnerability, which was classified as problematic, was found in Craft CMS up to 4.16.17/5.8.21. The affected element is the function assembleLayoutFromPost of the file src/services/Fields.php. Such manipulation leads to use of externally-controlled input to select classes or code.
This vulnerability is uniquely identified as CVE-2026-25498. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.