StatewardStateward
PlatformPricingComplianceVulnerabilitiesCase studiesDocsBlogAbout
enfr
Book a Demo / ContactGet started free
← All vulnerabilities
HIGHSupply chain

CVE-2026-54718

Packagist · symbiote/silverstripe-advancedworkflow

Summary

silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template

Advisory details

Impact

The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.

Reported by

Steve Boyd Silverstripe Ltd.

References

  • https://github.com/advisories/GHSA-39mm-rwm3-29jp
  • https://github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jp
  • https://github.com/silverstripe/silverstripe-advancedworkflow/pull/629
  • https://github.com/silverstripe/silverstripe-advancedworkflow/pull/630
  • https://github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bb
  • https://github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678b
  • https://github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-advancedworkflow/CVE-2026-54718.yaml
  • https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5
SourceStateward
Severityhigh
CVSS7.2
EPSS0.7% (p52)
Also known asGHSA-39mm-rwm3-29jp
CWECWE-20, CWE-1336
Added2026-08-27

Is your project exposed to this? Stateward checks every dependency on every pull request, and flags it only if your code actually reaches it.

Check my repo
Summarize with
ChatGPTClaudePerplexity

Related vulnerabilities

All Supply chain →
  • HIGHCVE-2026-72807

    SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

  • CRITICALCVE-2026-62681

    Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

  • CRITICALCVE-2026-62682

    Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

  • CRITICALCVE-2026-72717

    Orval: Import-time RCE via schema default -> zod module-level template literal

  • CRITICALCVE-2026-71869

    Orval: Import-time RCE via array-items default -> zod module-level template literal

  • CRITICALCVE-2026-71871

    Orval: Import-time RCE via header-parameter default -> zod module-level template literal

StatewardStateward

Autonomous cybersecurity for your entire codebase.

A venture of Yggdrasil Digital.

Product

  • Platform
  • What we detect
  • How we protect you
  • Pricing
  • Compliance
  • Vulnerabilities
  • Blog
  • Get started free

Resources

  • Breach breakdowns
  • Merge-induced flaws
  • Docs
  • Sample finding
  • Glossary
  • Compare
  • Threat feed API ↗

Company

  • About
  • Yggdrasil Digital ↗

Legal

  • Legal notice
  • Terms of Use
  • Terms of Sale
  • Privacy
  • Cookies
  • DPA

Connect

  • GitHub ↗
  • X ↗
  • Yggdrasil Digital ↗
  • Threat feed (RSS) ↗
  • hello@stateward.com

Stateward provides automated security analysis and does not guarantee detection of all vulnerabilities. It is designed to support, not replace, sound security practices and human judgement.

© 2026 Stateward. All rights reserved.A Yggdrasil Digital venture