7.3
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Description
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an asset. Version 7.23.0 contains a fix.
Basic Information
ID
CVE-2026-41172
Source
GitHub_M
Published
Apr 22, 2026 at 21:22
Affected Product
Vendor
Squidex
Product
squidex
Version
< 7.23.0
Affected Versions
Squidex squidex < 7.23.0