HIGH 7.2
GHSA-39mm-rwm3-29jp
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
Quick fix
GHSA-39mm-rwm3-29jp — symbiote/silverstripe-advancedworkflow: upgrade to the fixed version with the command below.
composer require symbiote/silverstripe-advancedworkflow:^6.4.5 Details
### Impact The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.
### Reported by Steve Boyd Silverstripe Ltd.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / symbiote/silverstripe-advancedworkflow
Introduced in:
0 Fixed in: 6.4.5 Fix
composer require symbiote/silverstripe-advancedworkflow:^6.4.5 Packagist / symbiote/silverstripe-advancedworkflow
Introduced in:
7.0.0 Fixed in: 7.1.3 Fix
composer require symbiote/silverstripe-advancedworkflow:^7.1.3 Packagist / symbiote/silverstripe-advancedworkflow
Introduced in:
7.2.0 Fixed in: 7.2.1 Fix
composer require symbiote/silverstripe-advancedworkflow:^7.2.1 References
- https://github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jp [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/pull/629 [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/pull/630 [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bb [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678b [WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symbiote/silverstripe-advancedworkflow/CVE-2026-54718.yaml [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow [PACKAGE]
- https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5 [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.1.3 [WEB]
- https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.2.1 [WEB]
- https://www.silverstripe.org/download/security-releases/cve-2026-54718 [WEB]