PKSA-24yr-dkzm-n9v5 Security Advisory
-
[LOW] Craft CMS has a potential information disclosure vulnerability in preview tokens
PKSA-24yr-dkzm-n9v5 CVE-2026-29113 GHSA-vg3j-hpm9-8v5v
Affected package: craftcms/cms
Affected version: >=5.0.0-RC1,<5.9.6|>=4.0.0-RC1,<4.17.3
Reported by:
GitHub