High severity7.2GHSA Advisory· Published Aug 27, 2026· Updated Aug 27, 2026
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
CVE-2026-54718
Description
Impact
The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.
Reported by
Steve Boyd Silverstripe Ltd.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3>= 7.2.0, < 7.2.1+ 1 more
- (no CPE)range: >= 7.2.0, < 7.2.1
- (no CPE)
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-39mm-rwm3-29jpghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-advancedworkflow/CVE-2026-54718.yamlghsa
- github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bbghsa
- github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678bghsa
- github.com/silverstripe/silverstripe-advancedworkflow/pull/629ghsa
- github.com/silverstripe/silverstripe-advancedworkflow/pull/630ghsa
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5ghsa
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.1.3ghsa
- github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.2.1ghsa
- github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jpghsa
- www.silverstripe.org/download/security-releases/cve-2026-54718ghsa
News mentions
0No linked articles in our index yet.