THREAT OPS › Threat News › [GHSA] GHSA-39mm-rwm3-29jp (high) — silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
[GHSA] GHSA-39mm-rwm3-29jp (high) — silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
GHSA-39mm-rwm3-29jp Severity: high CVE: CVE-2026-54718
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
### Impact The advanced workflow email template field is vulnerable to a specially crafted payload that can be used to run arbitrary code on the server.
### Reported by Steve Boyd Silverstripe Ltd.
Indicators of compromise
- CVE-2026-54718cve
Original source: https://github.com/advisories/GHSA-39mm-rwm3-29jp