CVE-2026-71435: Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
The default (“automagic”) form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submitter to inject HTML into the notification emails sent to the configured recipients
References
- github.com/advisories/GHSA-vx89-p3j7-8xqc
- github.com/statamic/cms/commit/4ad1335e818a67249d0617f0f167a1198fb96a2c
- github.com/statamic/cms/pull/14959
- github.com/statamic/cms/releases/tag/v5.74.3
- github.com/statamic/cms/releases/tag/v6.24.2
- github.com/statamic/cms/security/advisories/GHSA-vx89-p3j7-8xqc
- nvd.nist.gov/vuln/detail/CVE-2026-71435
Code Behaviors & Features
Detect and mitigate CVE-2026-71435 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →