lowVulnerability

GHSA-44px-qjjc-xrhq

### Summary An authenticated low-privileged user can call `assets/preview-file` for an asset they are not authorized to view and still receive preview response data (`previewHtml`) for that private asset. The returned preview HTML included a private preview image route containing the target private `assetId`, even though `canView` was `false` for the attacker account. ### Details 1. `assets/preview-file` accepts a maliciously controlled `assetId` and renders preview output. 2. The action does not enforce per-asset view authorization prior to returning preview content. 3. As a result, an authenticated user without asset-view permission can still obtain private preview output. This affects Craft installations with authenticated users of mixed privilege levels with private assets. ### Resources - d30df3112220db1ffd6726a3ed11857014c7fb27 - b1cddf72c98a

Properties

ghsa_id
GHSA-44px-qjjc-xrhq
severity
low
summary
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
cve_id
GHSA-44px-qjjc-xrhq
is_ghsa_only
true
ghsa_published
2026-03-26T17:12:21Z
source_url
https://github.com/advisories/GHSA-44px-qjjc-xrhq
ghsa_updated
2026-03-26T17:12:25Z

Related Entities (5)

AFFECTS (1)

[Software]composer/craftcms/cms

HAS_WEAKNESS (3)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
[Weakness]Missing Authorization
[Weakness]Authorization Bypass Through User-Controlled Key

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-44px-qjjc-xrhq — Ninja Signal Threat Intelligence | Ninja Signal