THREAT OPS › Threat News › [GHSA] GHSA-g8wr-r2v2-vqc6 (high) — silverstripe/userforms vulnerable to remote code execution via userforms email subject
[GHSA] GHSA-g8wr-r2v2-vqc6 (high) — silverstripe/userforms vulnerable to remote code execution via userforms email subject
GHSA-g8wr-r2v2-vqc6 Severity: high CVE: CVE-2026-54721
silverstripe/userforms vulnerable to remote code execution via userforms email subject
### Impact The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
### Reported by Jack Wallace from Bastion Security
Indicators of compromise
- CVE-2026-54721cve
Original source: https://github.com/advisories/GHSA-g8wr-r2v2-vqc6