CVE-2026-55779
Description
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and $changedProperty['value'] without applying Convert::raw2xml(). When an administrator restores an archived page containing a crafted title or URL segment, the generated restoration message can execute stored JavaScript in the administrator's browser, compromising the confidentiality and integrity of the CMS session. This issue is fixed in version 3.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.2.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-m4g4-86qc-v8w7ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yamlghsa
- github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952nvd
- github.com/silverstripe/silverstripe-versioned/pull/541nvd
- github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1nvd
- github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7nvd
- www.silverstripe.org/download/security-releases/cve-2026-55779nvd
News mentions
0No linked articles in our index yet.