VYPR
High severity7.2GHSA Advisory· Published Aug 27, 2026· Updated Sep 9, 2026

CVE-2026-54718

CVE-2026-54718

Description

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When NotifyUsersWorkflowAction renders the field through the Silverstripe template engine SSTemplateParser, the payload can cause PHP evaluation and arbitrary code execution on the server; the regression coverage is in tests/php/WorkflowEngineTest.php. This issue is fixed in versions 6.4.5, 7.1.3, and 7.2.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
symbiote/silverstripe-advancedworkflowPackagist
< 6.4.56.4.5
symbiote/silverstripe-advancedworkflowPackagist
>= 7.0.0, < 7.1.37.1.3
symbiote/silverstripe-advancedworkflowPackagist
>= 7.2.0, < 7.2.17.2.1

Affected products

3

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.