CVE-2026-25492 | Craft CMS up to 4.16.17/5.8.21 GraphQL Mutation save_images_Asset server-side request forgery (GHSA-96pq-hxpw-rgh8)
A vulnerability was found in Craft CMS up to 4.16.17/5.8.21. It has been rated as critical. Affected by this vulnerability is the function save_images_Asset of the component GraphQL Mutation Handler. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2026-25492. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.