{"id":"CVE-2026-54718","summary":"Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template","details":"Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When NotifyUsersWorkflowAction renders the field through the Silverstripe template engine SSTemplateParser, the payload can cause PHP evaluation and arbitrary code execution on the server; the regression coverage is in tests/php/WorkflowEngineTest.php. This issue is fixed in versions 6.4.5, 7.1.3, and 7.2.1.","aliases":["GHSA-39mm-rwm3-29jp"],"modified":"2026-08-29T03:47:10.677560669Z","published":"2026-08-27T17:19:51.691Z","database_specific":{"cwe_ids":["CWE-1336"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54718.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/6.4.5"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.1.3"},{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/releases/tag/7.2.1"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/cve-2026-54718"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54718.json"},{"type":"ADVISORY","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/security/advisories/GHSA-39mm-rwm3-29jp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54718"},{"type":"FIX","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/commit/28d0b536491e5c68b1c445579bdd1ddc8beaf8bb"},{"type":"FIX","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/commit/f170766af992ed2ed3e5f21d127d0d0d3129678b"},{"type":"FIX","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/pull/629"},{"type":"FIX","url":"https://github.com/silverstripe/silverstripe-advancedworkflow/pull/630"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/silverstripe/silverstripe-advancedworkflow","events":[{"introduced":"0"},{"introduced":"c40d774ccec59872dc95fc2d95a4365db3afdc18"},{"introduced":"063cd839c6c0204eac743b2eefb78f1585eea766"},{"fixed":"f170766af992ed2ed3e5f21d127d0d0d3129678b"},{"fixed":"28d0b536491e5c68b1c445579bdd1ddc8beaf8bb"},{"fixed":"8c4570aa115d97e8175968bf39020efdee60effc"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.4.5"},{"introduced":"7.0.0"},{"fixed":"7.1.3"},{"introduced":"7.2.0"},{"fixed":"7.2.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["7.2.0-rc1","7.2.0-beta1","7.2.0","6.4.4","7.1.2","6.4.3","7.1.1","7.1.0-rc1","7.1.0","6.4.2","7.1.0-beta1","6.4.1","6.4.0","6.4.0-rc1","6.4.0-beta1","7.0.0-alpha1","6.3.0-rc1","6.3.0-beta1","6.3.0","6.2.0-beta1","6.1.0-beta1","6.0.0-beta1","5.7.0","5.6.0-beta1","5.5.0-rc1","5.5.0-beta1","5.5.0-alpha1","5.5.0","5.4.0-beta1","5.0.4","5.0.3","5.0.2","5.0.1","5.0.0","3.3.2","3.3.1","3.3.0","3.2.3","3.2.2","3.2.1","3.2.0","3.1.2","3.1.1","3.1.0","3.0.6","3.0.5","3.0.4","3.0.3","3.0.2","3.0.1-rc1","3.0.1","2.1.0","2.0.0","1.3.1","1.3.0","1.2.0","1.1.1","1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54718.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}