GHSA-44px-qjjc-xrhqLow

Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata

Published
March 26, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

An authenticated low-privileged user can call assets/preview-file for an asset they are not authorized to view and still receive preview response data (previewHtml) for that private asset.

The returned preview HTML included a private preview image route containing the target private assetId, even though canView was false for the attacker account.

Details

  1. assets/preview-file accepts a maliciously controlled assetId and renders preview output.
  2. The action does not enforce per-asset view authorization prior to returning preview content.
  3. As a result, an authenticated user without asset-view permission can still obtain private preview output.

This affects Craft installations with authenticated users of mixed privilege levels with private assets.

Resources

  • d30df3112220db1ffd6726a3ed11857014c7fb27
  • b1cddf72c98a

🎯 Affected products2

  • composer/craftcms/cms:>= 5.0.0-RC1, <= 5.9.13
  • composer/craftcms/cms:>= 4.0.0-RC1, <= 4.17.7

🔗 References (6)