MEDIUM5.4
GHSA-m4g4-86qc-v8w7
silverstripe/versioned has XSS in archive admin restore
Quick fix
GHSA-m4g4-86qc-v8w7 — silverstripe/versioned: upgrade to the fixed version with the command below.
composer require silverstripe/versioned:^3.2.1Details
### Impact It's possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
### Reporter Steve Boyd Silverstripe Ltd.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/silverstripe/versioned
Introduced in:
0Fixed in: 3.2.1Fix
composer require silverstripe/versioned:^3.2.1References
- https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7[WEB]
- https://github.com/silverstripe/silverstripe-versioned/pull/541[WEB]
- https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yaml[WEB]
- https://github.com/silverstripe/silverstripe-versioned[PACKAGE]
- https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1[WEB]
- https://www.silverstripe.org/download/security-releases/cve-2026-55779[WEB]