Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Vendors & Products |
Craftcms
Craftcms craft Cms |
Mon, 05 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. | |
| Title | Craft CMS vulnerable to potential information disclosure via unchecked asset relocation | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-05T21:46:01.734Z
Updated: 2026-01-06T17:38:37.097Z
Reserved: 2025-12-17T15:43:01.352Z
Link: CVE-2025-68436
Updated: 2026-01-06T15:41:52.551Z
Status : Received
Published: 2026-01-05T22:15:52.117
Modified: 2026-01-05T22:15:52.117
Link: CVE-2025-68436
No data.