A AegiFlow
HIGHCVSS 7.2EPSS 0.7%

CVE-2026-54718

CVE-2026-54718 updated by NVD

Published
2026-08-27
Modified
2026-09-11
EPSS percentile
51%
Sources
github-advisory, nvd

Summary

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When NotifyUsersWorkflowAction renders the field through the Silverstripe template engine SSTemplateParser, the payload can cause PHP evaluation and arbitrary code execution on the server; the regression coverage is in tests/php/WorkflowEngineTest.php. This issue is fixed in versions 6.4.5, 7.1.3, and 7.2.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistsymbiote/silverstripe-advancedworkflow6.4.5, 7.1.3, 7.2.1

Remediation: Upgrade to 6.4.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.