VYPR
Medium severityNVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026

CVE-2026-55791

CVE-2026-55791

Description

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
>= 5.0.0-RC1, < 5.105.10
craftcms/cmsPackagist
>= 4.0.0-RC1, < 4.184.18

Affected products

1
  • Craftcms/CMSllm-fuzzy
    Range: >=4.0.0-RC1, <4.18.0, >=5.0.0-RC1, <5.10.0

Patches

Vulnerability mechanics

References

3

News mentions

1