Description
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file
Published: 2026-04-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Upgrade
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8wmw-prw8-2ggm Craftql vulnerable to Server-Side Request Forgery
History

Mon, 20 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
Title Server‑Side Request Forgery in Craftql Enables Arbitrary Code Execution

Mon, 20 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Title SSRF in Craftql Enabling Arbitrary Code Execution
Weaknesses CWE-78

Mon, 20 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
Title SSRF in Craftql Enabling Arbitrary Code Execution
Weaknesses CWE-78
CWE-918

Fri, 17 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Markhuot
Markhuot craftql
Vendors & Products Markhuot
Markhuot craftql

Fri, 17 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Description Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file
References

Subscriptions

Markhuot Craftql
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-20T14:59:43.878Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31317

cve-icon Vulnrichment

Updated: 2026-04-17T14:54:33.189Z

cve-icon NVD

Status : Deferred

Published: 2026-04-17T14:16:33.730

Modified: 2026-04-20T16:16:42.660

Link: CVE-2026-31317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T18:45:14Z

Weaknesses