{"id":"GHSA-hcch-w73c-jp4m","summary":"Statamic vulnerable to privilege escalation via stored cross-site scripting","details":"### Impact\n\nStored XSS in the control panel color mode preference allows authenticated users with control panel access to inject malicious JavaScript that executes when a higher-privileged user impersonates their account.\n\n### Patches\n\nThis has been fixed in 6.6.2.","aliases":["CVE-2026-32612"],"modified":"2026-03-16T17:16:53.164579Z","published":"2026-03-13T20:50:51Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-13T20:50:51Z","nvd_published_at":"2026-03-13T19:55:09Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/statamic/cms/security/advisories/GHSA-hcch-w73c-jp4m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32612"},{"type":"WEB","url":"https://github.com/Shirshaw64p/security-advisories/tree/main/CVE-2026-32612"},{"type":"PACKAGE","url":"https://github.com/statamic/cms"}],"affected":[{"package":{"name":"statamic/cms","ecosystem":"Packagist","purl":"pkg:composer/statamic/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.6.2"}]}],"versions":["v6.0.0","v6.1.0","v6.2.0","v6.2.1","v6.2.2","v6.2.3","v6.2.4","v6.2.5","v6.3.0","v6.3.1","v6.3.2","v6.3.3","v6.4.0","v6.4.1","v6.5.0","v6.6.0","v6.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hcch-w73c-jp4m/GHSA-hcch-w73c-jp4m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}