CVE-2026-55791Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-644CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-07-02: 4Technical Details · 2026-07-02: 307-02
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • Aretiq.AI@AretiqAI
    General

    ARETIQ Daily Vulnerability Bulletin — July 02, 2026 🔴 CRITICAL: CVE-2026-55791 (craftcms/cms) AAS 12.8 11 vulnerabilities — CRITICAL: 1, HIGH: 10 Full bulletin: https://aretiq.ai/bulletins/2026-07-02/

    Post summary

    The bulletin announces CVE-2026-55791 for craftcms/cms as a critical issue, listing severity data and a link to the full bulletin, but provides no further technical, exploit, or mitigation details.

    00021198
    227 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-55791 Server-Side Request Forgery and Arbitrary JavaScript Injection in Craft CMS https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-55791

    Post summary

    The text announces CVE‑2026‑55791, describing SSRF and JavaScript injection in Craft CMS, without mentioning PoC, exploit code, or active exploitation.

    00001122
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55791 Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side… https://www.cve.org/CVERecord?id=CVE-2026-55791 ----- Traducción: CVE-2026-55791 Cra… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-55791 for Craft CMS, notes the vulnerable version ranges and Server‑Side exploitation type, but provides neither PoC, exploit code, active usage, mitigation, nor debunking info.

    0000036
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55791 Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side… https://www.cve.org/CVERecord?id=CVE-2026-55791

    Post summary

    The post announces a new Craft CMS vulnerability (CVE‑2026‑55791) affecting specific releases, noting a server‑side issue, but offers no PoC, exploit code, active exploitation, patch, or mitigation details.

    00000682
    57.7K followersView on X

Explore more