Skip to content

Potential information disclosure via unchecked asset relocation

Moderate
angrybrad published GHSA-53vf-c43h-j2x9 Jan 3, 2026

Package

composer craftcms/cms (Composer)

Affected versions

>= 5.0.0-RC1, <= 5.8.20
>= 4.0.0-RC1, <= 4.16.16

Patched versions

5.8.21
4.16.17

Description

Authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests.

Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

References:

4bcb0db

4bcb0db

Severity

Moderate

CVE ID

CVE-2025-68436

Weaknesses

No CWEs

Credits