Résumé
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Détails de l’avis
Impact
Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.
Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.
Patches
This has been fixed in 5.74.1 and 6.24.0.
Références
Vulnérabilités liées
Tout Supply chain →- CRITICALCVE-2026-55559
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
- MEDIUMCVE-2026-54614
cakephp/debug_kit: MailPreview contains unsafe reflection
- HIGHCVE-2026-68508
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
- CRITICALCVE-2026-55107
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
- HIGHCVE-2026-63337
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
- HIGHCVE-2026-55153
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"