Summary
silverstripe/userforms vulnerable to remote code execution via userforms email subject
Advisory details
Impact
The userform email subject field in the CMS is vulnerable to a specially crafted payload being used to run arbitrary code on the server.
Reported by
Jack Wallace from Bastion Security
References
- https://github.com/advisories/GHSA-g8wr-r2v2-vqc6
- https://github.com/silverstripe/silverstripe-userforms/security/advisories/GHSA-g8wr-r2v2-vqc6
- https://github.com/silverstripe/silverstripe-userforms/pull/1441
- https://github.com/silverstripe/silverstripe-userforms/pull/1442
- https://github.com/silverstripe/silverstripe-userforms/commit/23c069866900c19b499bfa997d1e251e97491702
- https://github.com/silverstripe/silverstripe-userforms/commit/c55494ad7c717b199a3c1663b43a54db5d95604c
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/userforms/CVE-2026-54721.yaml
- https://github.com/silverstripe/silverstripe-userforms/releases/tag/6.4.9
Related vulnerabilities
All Supply chain →- CRITICALCVE-2026-54133
jmespath.php has CompilerRuntime code injection via unescaped function names
- HIGHCVE-2026-75911
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
- HIGHCVE-2026-75858
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
- CRITICALCVE-2026-62681
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
- CRITICALCVE-2026-62682
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
- CRITICALCVE-2026-72717
Orval: Import-time RCE via schema default -> zod module-level template literal