CVE-2026-64663 MEDIUM

CVE-2026-64663: Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

Vendor Statamic
Product cms
Weakness CWE-470
Published August 6, 2026
Last update August 7, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.

Key dates

02Disclosure timeline

August 6, 2026 CVE published
August 7, 2026 Record updated