Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
History

Tue, 06 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Craftcms
Craftcms craft Cms
Vendors & Products Craftcms
Craftcms craft Cms

Mon, 05 Jan 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Title Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 4.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-01-05T21:46:01.734Z

Updated: 2026-01-06T17:38:37.097Z

Reserved: 2025-12-17T15:43:01.352Z

Link: CVE-2025-68436

cve-icon Vulnrichment

Updated: 2026-01-06T15:41:52.551Z

cve-icon NVD

Status : Received

Published: 2026-01-05T22:15:52.117

Modified: 2026-01-05T22:15:52.117

Link: CVE-2025-68436

cve-icon Redhat

No data.