THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-39mm-rwm3-29jp (high) — silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template

[GHSA] GHSA-39mm-rwm3-29jp (high) — silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template

medgithub_advisoriesPublished 2026-08-27

GHSA-39mm-rwm3-29jp Severity: high CVE: CVE-2026-54718

silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template

### Impact The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.

### Reported by Steve Boyd Silverstripe Ltd.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-39mm-rwm3-29jp