CVE-2025-68436
Unknown Unknown - Not Provided
Information Disclosure via User Profile Photo in Craft CMS

Publication date: 2026-01-05

Last updated on: 2026-01-05

Assigner: GitHub, Inc.

Description
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-05
Last Modified
2026-01-05
Generated
2026-06-16
AI Q&A
2026-01-06
EPSS Evaluated
2026-06-14
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
craftcms craft 5.8.21
craftcms craft 4.16.17
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects the Craft platform versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16. Authenticated users on a Craft installation could potentially expose sensitive assets through their user profile photo by sending maliciously crafted requests. The issue can be mitigated by updating to the patched versions 5.8.21 and 4.16.17.

Impact Analysis

The vulnerability could lead to the exposure of sensitive assets via user profile photos, which may compromise confidentiality of information stored or displayed on the Craft platform. This could result in unauthorized access to sensitive data by authenticated users exploiting the flaw.

Mitigation Strategies

Update your Craft installation to the patched versions 5.8.21 or 4.16.17 to mitigate the vulnerability related to exposure of sensitive assets via user profile photos.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-68436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart