GHSA-gvrw-qqp5-jgc5: XSS
Published Aug 27, 2026
·Updated
Impact The "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed.
Reported by Jack Wallace from Bastion Security
Affected Software
1 affected componentFixes available
composer/silverstripe/framework<6.2.2
6.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/silverstripe/frameworkto a version that resolves this vulnerability.Fixed in 6.2.2
Event History
Aug 27, 2026
Advisory Published
via GitHub·04:49 PM
Data Sourced
via GitHub·04:49 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What user interaction is required for exploitation?
Exploitation requires a user to interact with specially crafted embedded media. The vulnerability is remotely reachable and does not require attacker privileges.
2
Which CMS feature should be prioritized during triage?
Prioritize the CMS "Insert media from web" functionality, as the reported XSS issue is triggered through a specially crafted embed.
3
What impact can successful exploitation have?
The supplied severity vector indicates low confidentiality and low integrity impact, with no availability impact.