THREAT OPS › Threat News › [GHSA] GHSA-qhr7-v3xp-vw9m (medium) — Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
[GHSA] GHSA-qhr7-v3xp-vw9m (medium) — Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
GHSA-qhr7-v3xp-vw9m Severity: medium CVE: CVE-2026-71434
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
### Impact Public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had intended to disallow through a form's `assets` or `files`
MITRE ATT&CK techniques
- Control PanelT1218.002
Indicators of compromise
- CVE-2026-71434cve
Original source: https://github.com/advisories/GHSA-qhr7-v3xp-vw9m