CVE-2026-54718
Description
Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When NotifyUsersWorkflowAction renders the field through the Silverstripe template engine SSTemplateParser, the payload can cause PHP evaluation and arbitrary code execution on the server; the regression coverage is in tests/php/WorkflowEngineTest.php. This issue is fixed in versions 6.4.5, 7.1.3, and 7.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symbiote/silverstripe-advancedworkflowPackagist | < 6.4.5 | 6.4.5 |
symbiote/silverstripe-advancedworkflowPackagist | >= 7.0.0, < 7.1.3 | 7.1.3 |
symbiote/silverstripe-advancedworkflowPackagist | >= 7.2.0, < 7.2.1 | 7.2.1 |
Affected products
3>= 7.2.0, < 7.2.1+ 1 more
- (no CPE)range: >= 7.2.0, < 7.2.1
- (no CPE)
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-39mm-rwm3-29jpghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-advancedworkflow/CVE-2026-54718.yamlghsaWEB
- github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bbnvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678bnvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/pull/629nvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/pull/630nvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5nvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.1.3nvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.2.1nvdWEB
- github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jpnvdWEB
- www.silverstripe.org/download/security-releases/cve-2026-54718nvdWEB
News mentions
0No linked articles in our index yet.