Skip to content

[CVE-2026-54721] Prevent RCE via email recipient subject - #1442

Merged
blueo merged 1 commit into
silverstripe:6.4from
creative-commoners:pulls/6.4/cve-email-rce
Jun 24, 2026
Merged

[CVE-2026-54721] Prevent RCE via email recipient subject#1442
blueo merged 1 commit into
silverstripe:6.4from
creative-commoners:pulls/6.4/cve-email-rce

Conversation

@emteknetnz

@emteknetnz emteknetnz commented Jun 24, 2026

Copy link
Copy Markdown
Member

endtoend failure is only for PHP 8.1 not for PHP 8.3 - CI uses an older version of gha-ci and would have passed if it has this fix backported (which we won't be backporting)

@NightJar

NightJar commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Please don't publicly disclose vulnerabilities until the fix is released.
Seems like this was the release, I'd not seen a CVE managed like this before.

@blueo
blueo merged commit c55494a into silverstripe:6.4 Jun 24, 2026
13 of 14 checks passed
@emteknetnz
emteknetnz deleted the pulls/6.4/cve-email-rce branch June 24, 2026 04:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants