THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qhr7-v3xp-vw9m (medium) — Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types

[GHSA] GHSA-qhr7-v3xp-vw9m (medium) — Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types

medgithub_advisoriesPublished 2026-08-06

GHSA-qhr7-v3xp-vw9m Severity: medium CVE: CVE-2026-71434

Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types

### Impact Public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had intended to disallow through a form's `assets` or `files`

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qhr7-v3xp-vw9m