### Requirements: * Control panel access * Permissions to edit an entry ### Details Control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header. The issue happens when a user is saving entries. Strings for a signed redirect URL are being compiled as a Twig template via `renderObjectTemplate()`, and while a sandboxed alternative already exists (`renderSandboxedObjectTemplate()`), it is not used in this case. This signed URL can be specified by users, as it is reflected in the “Referer” HTTP request header, which is under attacker control. This has been fixed in Craft 5.10.0. Affected users should update to that version or higher to get the fix. ### Resources https://github.com/craftcms/cms/pull/18680
Update craftcms/cms to 5.10.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCraft CMS: Potential authenticated Remote Code Execution via referrer redirect affects craftcms/cms (composer). Severity is high. ### Requirements: * Control panel access * Permissions to edit an entry ### Details Control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header. The issue happens when a user is saving entries. Strings for a signed redirect URL are being compiled as a Twig template via `renderObjectTemplate()`, and while a sandboxed alternative already exists (`renderSandboxedObjectTemplate()`), it is not used in this case. This signed URL can be specified by users, as it is reflected in the “Referer” HTTP request header, which is under attacker control. This has been fixed in Craft 5.10.0. Affected users should update to that version or higher to get the fix. ### Resources https://github.com/craftcms/cms/pull/18680
AI coding agents often install or upgrade packages automatically in composer. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
### Requirements: * Control panel access * Permissions to edit an entry ### Details Control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header. The issue happens when a user is saving entries. Strings for a signed redirect URL are being compiled as a Twig template via `renderObjectTemplate()`, and while a sandboxed alternative already exists (`renderSandboxedObjectTemplate()`), it is not used in this case. This signed URL can be specified by users, as it is reflected in the “Referer” HTTP request header, which is under attacker control. This has been fixed in Craft 5.10.0. Affected users should update to that version or higher to get the fix. ### Resources https://github.com/craftcms/cms/pull/18680
Update craftcms/cms to 5.10.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCraft CMS: Potential authenticated Remote Code Execution via referrer redirect affects craftcms/cms (composer). Severity is high. ### Requirements: * Control panel access * Permissions to edit an entry ### Details Control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header. The issue happens when a user is saving entries. Strings for a signed redirect URL are being compiled as a Twig template via `renderObjectTemplate()`, and while a sandboxed alternative already exists (`renderSandboxedObjectTemplate()`), it is not used in this case. This signed URL can be specified by users, as it is reflected in the “Referer” HTTP request header, which is under attacker control. This has been fixed in Craft 5.10.0. Affected users should update to that version or higher to get the fix. ### Resources https://github.com/craftcms/cms/pull/18680
AI coding agents often install or upgrade packages automatically in composer. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| craftcms/cmscomposer | >=5.9.0,<5.10.0 | 5.10.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| craftcms/cmscomposer | >=5.9.0,<5.10.0 | 5.10.0 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard