---
id: CVE-2026-64663
title: Statamic is a Laravel and Git powered content management system (CMS)
summary: >-
  Statamic is a Laravel and Git powered content management system (CMS). Prior
  to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into
  Antlers templates could result in the loss of content and assets, on sites
  whose templa…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-470
vendor: statamic
product: statamic/cms
affected:
  - statamic/cms < 5.74.1
  - 'statamic/cms >= 6.0.0, < 6.24.0'
patched:
  - statamic/cms 5.74.1
  - statamic/cms 6.24.0
published: '2026-08-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:51:43.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64663'
references:
  - url: 'https://github.com/statamic/cms/security/advisories/GHSA-j2vp-f2pv-5rj4'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-j2vp-f2pv-5rj4'
tags:
  - nvd
  - ghsa
  - composer
epss: 0.00296
epssPercentile: 0.22491
aliases:
  - GHSA-j2vp-f2pv-5rj4
ecosystem: composer
ingestedAt: '2026-08-06T20:03:56.627Z'
---

## Overview

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templates pass untrusted input into affected areas, and exploitation did not require authentication. This issue is fixed in versions 5.74.1 and 6.24.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-64663)

Affected packages:

- `statamic/cms < 5.74.1`
- `statamic/cms >= 6.0.0, < 6.24.0`

Patched in:

- `statamic/cms 5.74.1`
- `statamic/cms 6.24.0`

Source: https://github.com/advisories/GHSA-j2vp-f2pv-5rj4
