GHSA-44px-qjjc-xrhq
### Summary An authenticated low-privileged user can call `assets/preview-file` for an asset they are not authorized to view and still receive preview response data (`previewHtml`) for that private asset. The returned preview HTML included a private preview image route containing the target private `assetId`, even though `canView` was `false` for the attacker account. ### Details 1. `assets/preview-file` accepts a maliciously controlled `assetId` and renders preview output. 2. The action does not enforce per-asset view authorization prior to returning preview content. 3. As a result, an authenticated user without asset-view permission can still obtain private preview output. This affects Craft installations with authenticated users of mixed privilege levels with private assets. ### Resources - d30df3112220db1ffd6726a3ed11857014c7fb27 - b1cddf72c98a
Properties
- ghsa_id
- GHSA-44px-qjjc-xrhq
- severity
- low
- summary
- Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
- cve_id
- GHSA-44px-qjjc-xrhq
- is_ghsa_only
- true
- ghsa_published
- 2026-03-26T17:12:21Z
- source_url
- https://github.com/advisories/GHSA-44px-qjjc-xrhq
- ghsa_updated
- 2026-03-26T17:12:25Z
Related Entities (5)
AFFECTS (1)
HAS_WEAKNESS (3)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph