A low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including focalPoint.
The endpoint returns private editing metadata without per-asset authorization validation.
Root-cause analysis:
actionImageEditor() accepts assetId from the request body.html and focalPoint.| Score | Percentile |
|---|---|
| 0.03% | 8.96% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 1.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-vgjg-248p-rfm2 ↗ |
| CVE | CVE-2026-33161 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | craftcms/cms | >= 5.0.0-RC1, <= 5.9.13 | 5.9.14 | — |
| composer | craftcms/cms | >= 4.0.0-RC1, <= 4.17.7 | 4.17.8 | — |