
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25759 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS that enables privilege escalation by allowing authenticated users with content creation permissions to inject malicious JavaScript into content titles. The injected script executes in the browser of any higher-privileged user — including super administrators — who views the affected content, potentially enabling unauthorized super admin account creation. It affects Statamic CMS versions 6.0.0 through 6.2.2 (Composer package statamic/cms) and was disclosed on February 11, 2026, with a patch released in version 6.2.3. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, Statamic Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in Statamic's command palette component (CommandPalette.vue). Content titles were rendered without HTML escaping in the command palette's fuzzy-search result highlighting logic, allowing raw HTML/JavaScript to be injected and later rendered as live DOM content when a privileged user opened the command palette. The fix, committed in 6ed4f65, introduced an escapeHtml() call via a new highlightResult() function that sanitizes text before passing it to fuzzysort's highlight renderer, preventing script injection (Statamic Commit, GitHub Advisory). Exploitation requires the attacker to hold a valid account with control panel access and content creation permissions, and a higher-privileged user must subsequently interact with the command palette while the malicious content title is present (Statamic Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of a higher-privileged user, including super administrators, resulting in high confidentiality and integrity impact with no availability impact. The most severe consequence is unauthorized creation of super admin accounts, effectively granting the attacker full administrative control over the Statamic CMS instance. Additional risks include session hijacking, credential theft, and exfiltration of sensitive data accessible to the compromised administrator (GitHub Advisory, Statamic Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.009–0.013%, placing it in the 2nd percentile for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported; the vulnerability was discovered and reported by a researcher credited as "Neosprings" (Statamic Advisory).
<img src=x onerror="fetch('/cp/users',{method:'POST',body:JSON.stringify({name:'attacker',email:'attacker@evil.com',super:true,password:'P@ssw0rd!',password_confirmation:'P@ssw0rd!'}),headers:{'Content-Type':'application/json','X-CSRF-TOKEN':document.querySelector('meta[name=csrf-token]').content}})">.fuzzysort highlight function, triggering script execution./cp/users) originating from a super admin session shortly after command palette usage; unusual admin account creation events in application audit logs.<script>, onerror=, javascript:).The primary remediation is to upgrade Statamic CMS to version 6.2.3 or later, which escapes HTML in command palette content titles before rendering (Statamic Release, GitHub Advisory). As interim measures, administrators should restrict control panel and content creation access to only fully trusted users, audit existing content entries for titles containing HTML or JavaScript, and implement a strict Content Security Policy (CSP) to limit the impact of any XSS execution. Monitoring for unexpected super admin account creation is also recommended until patching is complete (Feedly).
The vulnerability was reported by a researcher credited as "Neosprings" and published by Statamic maintainer jasonvarga on February 11, 2026. Coverage appeared on security aggregation sites including The Hacker Wire and Infinitsec shortly after disclosure, with community discussion noting the privilege escalation potential as particularly impactful for multi-user Statamic deployments (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."