CVE-2026-31317
HIGHCraftql <=1.3.7 - SSRF
Title source: llmDescription
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-918
Status
published
Products (1)
markhuot/craftql
0Packagist
Published
Apr 17, 2026
Tracked Since
Apr 17, 2026