Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j2vp-f2pv-5rj4 | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction |
Fri, 07 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0. | |
| Title | Statamic: Unsafe method invocation via Antlers template resolution allows data destruction | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-06T19:28:06.165Z
Reserved: 2026-07-20T17:11:30.896Z
Link: CVE-2026-64663
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:15:04Z
-
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Github GHSA