
CVE-2026-25494 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses f… https://www.cve.org/CVERecord?id=CVE-2026-25494
Post summary
CVE-2026-25494 involves a flaw in Craft’s saveAsset GraphQL mutation, but the text offers no evidence of exploitation, a PoC, or a patch.


