CVE-2025-68436
Unknown Unknown - Not Provided
Information Disclosure via User Profile Photo in Craft CMS

Publication date: 2026-01-05

Last updated on: 2026-01-05

Assigner: GitHub, Inc.

Description
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-05
Last Modified
2026-01-05
Generated
2026-05-27
AI Q&A
2026-01-06
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
craftcms craft 5.8.21
craftcms craft 4.16.17
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects the Craft platform versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16. Authenticated users on a Craft installation could potentially expose sensitive assets through their user profile photo by sending maliciously crafted requests. The issue can be mitigated by updating to the patched versions 5.8.21 and 4.16.17.


How can this vulnerability impact me? :

The vulnerability could lead to the exposure of sensitive assets via user profile photos, which may compromise confidentiality of information stored or displayed on the Craft platform. This could result in unauthorized access to sensitive data by authenticated users exploiting the flaw.


What immediate steps should I take to mitigate this vulnerability?

Update your Craft installation to the patched versions 5.8.21 or 4.16.17 to mitigate the vulnerability related to exposure of sensitive assets via user profile photos.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart