CVE-2026-29113 | Craft CMS up to 4.17.2/5.9.5 Endpoint create-token cross-site request forgery (GHSA-vg3j-hpm9-8v5v)
A vulnerability has been found in Craft CMS up to 4.17.2/5.9.5 and classified as problematic. The affected element is an unknown function of the file /actions/preview/create-token of the component Endpoint. The manipulation leads to cross-site request forgery.
This vulnerability is listed as CVE-2026-29113. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.