Description
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gcqf-5x9f-hq7f | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields |
References
History
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2. | |
| Title | Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T20:40:22.577Z
Reserved: 2026-03-24T15:10:05.681Z
Link: CVE-2026-33886
No data.
Status : Received
Published: 2026-03-27T21:17:25.490
Modified: 2026-03-27T21:17:25.490
Link: CVE-2026-33886
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA