{"id":"CVE-2026-54718","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54718","summary":"silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template","details":"### Impact\nThe advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.\n\n### Reported by\nSteve Boyd\nSilverstripe Ltd.","published":"2026-08-27T17:20:40Z","modified":"2026-08-27T17:30:06.766273296Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"symbiote/silverstripe-advancedworkflow","fixedVersion":"6.4.5"},{"ecosystem":"Packagist","name":"symbiote/silverstripe-advancedworkflow","fixedVersion":"7.1.3"},{"ecosystem":"Packagist","name":"symbiote/silverstripe-advancedworkflow","fixedVersion":"7.2.1"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-advancedworkflow/pull/629","label":"silverstripe/silverstripe-advancedworkflow#629"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jp"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/pull/629"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/pull/630"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bb"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678b"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-advancedworkflow/CVE-2026-54718.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-advancedworkflow"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.1.3"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.2.1"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/cve-2026-54718"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T17:30:06.766273296Z"}}