CVE-2026-31317 is a Server-Side Request Forgery (SSRF) vulnerability affecting Craftql versions 1.3.7 and earlier, specifically within the GetAssetsFieldSchema.php file. This flaw enables attackers to execute arbitrary code on vulnerable systems, potentially allowing unauthorized command execution and system compromise. The vulnerability is classified as actively exploited based on its placement on the Hot List. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, indicating significant risk to affected organizations. The attack vector is network-based with low complexity and requires no user interaction or special privileges, making exploitation straightforward for threat actors. The primary impact is confidentiality breach through unauthorized information disclosure, though integrity and availability are not directly affected by this particular variant. Exploitation status indicates this vulnerability is receiving active community attention and appears in exploitation tracking systems. The FAUCET Risk Score of 48.0/100 reflects moderate-to-high risk prioritization, though the vulnerability does not currently appear on the official Known Exploited Vulnerabilities (KEV) catalog. Organizations running Craftql should prioritize patching to versions above 1.3.7 to mitigate exposure to this actively tracked threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.