CVE-2026-64663

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 22:18

Updated : 2026-09-08 20:51


NVD link : CVE-2026-64663

Mitre link : CVE-2026-64663

CVE.ORG link : CVE-2026-64663


JSON object : View

Products Affected

No product.

CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')