Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS versions 4.0.0-RC1 through 4.17.7 and 5.0.0-RC1 through 5.9.13 contain a missing authorization vulnerability in the assets/preview-thumb endpoint. This flaw allows Control Panel users without asset-view permission to obtain a signed fallback transform preview link for private assets by calling the endpoint with an attacker-controlled assetId. The vulnerability is fixed in versions 4.17.8 and 5.9.14.
AI Analysis
Technical Summary
Craft CMS has a missing authorization vulnerability (CWE-862) in the assets/preview-thumb endpoint. Control Panel users lacking permission to view a private asset can invoke this endpoint with a crafted assetId and receive preview HTML that includes a signed fallback transform preview link for that asset. This occurs because the system does not perform an asset-view permission check before generating the preview. The issue affects versions >=4.0.0-RC1 and <=4.17.7, and >=5.0.0-RC1 and <=5.9.13, and is resolved in versions 4.17.8 and 5.9.14.
Potential Impact
An authenticated Control Panel user without permission to view certain private assets can obtain signed preview links to those assets, potentially exposing private asset information. The impact is limited to confidentiality (partial information disclosure) and does not affect integrity or availability.
Mitigation Recommendations
Upgrade Craft CMS to version 4.17.8 or later in the 4.x series, or 5.9.14 or later in the 5.x series, where this vulnerability has been fixed. No other mitigations are indicated.
Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Description
Craft CMS versions 4.0.0-RC1 through 4.17.7 and 5.0.0-RC1 through 5.9.13 contain a missing authorization vulnerability in the assets/preview-thumb endpoint. This flaw allows Control Panel users without asset-view permission to obtain a signed fallback transform preview link for private assets by calling the endpoint with an attacker-controlled assetId. The vulnerability is fixed in versions 4.17.8 and 5.9.14.
CVSS v3.1
Score 4.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Craft CMS has a missing authorization vulnerability (CWE-862) in the assets/preview-thumb endpoint. Control Panel users lacking permission to view a private asset can invoke this endpoint with a crafted assetId and receive preview HTML that includes a signed fallback transform preview link for that asset. This occurs because the system does not perform an asset-view permission check before generating the preview. The issue affects versions >=4.0.0-RC1 and <=4.17.7, and >=5.0.0-RC1 and <=5.9.13, and is resolved in versions 4.17.8 and 5.9.14.
Potential Impact
An authenticated Control Panel user without permission to view certain private assets can obtain signed preview links to those assets, potentially exposing private asset information. The impact is limited to confidentiality (partial information disclosure) and does not affect integrity or availability.
Mitigation Recommendations
Upgrade Craft CMS to version 4.17.8 or later in the 4.x series, or 5.9.14 or later in the 5.x series, where this vulnerability has been fixed. No other mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xj2c-g5xp-4p47
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7573bfbf8831d539d943d0
Added to database: 08/07/2026, 05:57:19 UTC
Last enriched: 08/07/2026, 07:00:57 UTC
Last updated: 08/07/2026, 09:43:44 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.