Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-31317

26
FAUCET Score

CVE-2026-31317 is a Server-Side Request Forgery (SSRF) vulnerability affecting Craftql versions 1.3.7 and earlier, specifically within the GetAssetsFieldSchema.php file. This flaw enables attackers to execute arbitrary code on vulnerable systems, potentially allowing unauthorized command execution and system compromise. The vulnerability is classified as actively exploited based on its placement on the Hot List. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, indicating significant risk to affected organizations. The attack vector is network-based with low complexity and requires no user interaction or special privileges, making exploitation straightforward for threat actors. The primary impact is confidentiality breach through unauthorized information disclosure, though integrity and availability are not directly affected by this particular variant. Exploitation status indicates this vulnerability is receiving active community attention and appears in exploitation tracking systems. The FAUCET Risk Score of 48.0/100 reflects moderate-to-high risk prioritization, though the vulnerability does not currently appear on the official Known Exploited Vulnerabilities (KEV) catalog. Organizations running Craftql should prioritize patching to versions above 1.3.7 to mitigate exposure to this actively tracked threat.

Impacted Technologies

VendorProductVersion(s)CPE
N/AN/A
n/aCNA affected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-8wmw-prw8-2ggmmedium

Craftql vulnerable to Server-Side Request Forgery

Apr 17, 2026

References

github.com / markhuot/craftql
github.com / stormmmg/craftql_ssrf
github.com / stormmmg/craftql_ssrf/blob/master/craftql-ssrf-en/README_detail.md