Junglewise Threat Intelligence

CVE-2026-55791: Craft CMS SSRF and JavaScript injection via Host header poisoning

CVE-2026-55791 · Severity: critical · CVSS 4 · Published 2026-07-02

Technologies: Craftcms CMS.

Executive brief

Craft CMS, a popular content management system, is vulnerable to a security flaw that allows attackers to trick the server into fetching malicious scripts from an external source. By manipulating web request headers, an attacker can force the system to serve harmful code to other users, including administrators. This can lead to unauthorized actions being performed on the site, such as the installation of malicious plugins or full site takeover if an administrator views a compromised page.

Technical details

A vulnerability exists in Craft CMS due to a combination of a permissive default 'trustedHosts' configuration and insecure URL validation in the 'AppController::actionResourceJs()' endpoint. An attacker can poison the 'Host' or 'X-Forwarded-Host' headers to manipulate the application's '$baseUrl', bypassing internal checks that ensure requested resources are local. The backend Guzzle client then fetches a remote payload from an attacker-controlled server and serves it with a 'application/javascript' content type. This can be leveraged for SSRF to probe internal networks or, more critically, for web cache poisoning to achieve Stored XSS and subsequent RCE via session riding. The issue is fixed in versions 4.18.0 and 5.10.0.

Affected products

  • craftcms cms >= 4.0.0-RC1, < 4.18.0; >= 5.0.0-RC1, < 5.10.0

Timeline

  • 2026-03-13: other: Initial bugfix pull request opened
  • 2026-04-21: patched: Fix merged into 4.18 branch
  • 2026-06-16: advisory: Security advisory published by vendor
  • 2026-07-02: disclosed: CVE published to NVD

References