GHSA-j2vp-f2pv-5rj4MediumCVSS 6.5

Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

Published
August 6, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.

Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.

Patches

This has been fixed in 5.74.1 and 6.24.0.

🎯 Affected products2

  • composer/statamic/cms:< 5.74.1
  • composer/statamic/cms:>= 6.0.0, < 6.24.0

🔗 References (2)