PT-2026-68967 · Packagist · Statamic Cms

Published

2026-08-06

·

Updated

2026-08-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Impact

Manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets.
Exploitation requires a site to have templates that pass untrusted input into affected areas. It does not require authentication.

Patches

This has been fixed in 5.74.1 and 6.24.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-J2VP-F2PV-5RJ4

Affected Products

Statamic Cms