Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and $changedProperty['value'] without applying Convert::raw2xml(). When an administrator restores an archived page containing a crafted title or URL segment, the generated restoration message can execute stored JavaScript in the administrator's browser, compromising the confidentiality and integrity of the CMS session. This issue is fixed in version 3.2.1.
Silverstripe Versioned: XSS in archive admin restore
Problem type
Affected products
silverstripe
< 3.2.1 - AFFECTED
References
https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7
https://github.com/silverstripe/silverstripe-versioned/pull/541
https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952
https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1
https://www.silverstripe.org/download/security-releases/cve-2026-55779
GitHub Security Advisories
GHSA-m4g4-86qc-v8w7
silverstripe/versioned has XSS in archive admin restore
https://github.com/advisories/GHSA-m4g4-86qc-v8w7Impact
It's possible to use the page title as an XSS vector when restoring a page in ArchiveAdmin
Reporter
Steve Boyd Silverstripe Ltd.
https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7
https://github.com/silverstripe/silverstripe-versioned/pull/541
https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/versioned/CVE-2026-55779.yaml
https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1
https://www.silverstripe.org/download/security-releases/cve-2026-55779
https://github.com/advisories/GHSA-m4g4-86qc-v8w7
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-55779Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-55779",
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"dateUpdated": "2026-08-28T22:18:57.661Z",
"dateReserved": "2026-06-17T14:40:28.379Z",
"datePublished": "2026-08-28T22:18:57.661Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M",
"dateUpdated": "2026-08-28T22:18:57.661Z"
},
"title": "Silverstripe Versioned: XSS in archive admin restore",
"descriptions": [
{
"lang": "en",
"value": "Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and $changedProperty['value'] without applying Convert::raw2xml(). When an administrator restores an archived page containing a crafted title or URL segment, the generated restoration message can execute stored JavaScript in the administrator's browser, compromising the confidentiality and integrity of the CMS session. This issue is fixed in version 3.2.1."
}
],
"affected": [
{
"vendor": "silverstripe",
"product": "silverstripe-versioned",
"versions": [
{
"version": "< 3.2.1",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"cweId": "CWE-79",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7",
"name": "https://github.com/silverstripe/silverstripe-versioned/security/advisories/GHSA-m4g4-86qc-v8w7",
"tags": [
"x_refsource_CONFIRM"
]
},
{
"url": "https://github.com/silverstripe/silverstripe-versioned/pull/541",
"name": "https://github.com/silverstripe/silverstripe-versioned/pull/541",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952",
"name": "https://github.com/silverstripe/silverstripe-versioned/commit/6e30a2cf8d4b9233690464da61bd0fc4d3e92952",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1",
"name": "https://github.com/silverstripe/silverstripe-versioned/releases/tag/3.2.1",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://www.silverstripe.org/download/security-releases/cve-2026-55779",
"name": "https://www.silverstripe.org/download/security-releases/cve-2026-55779",
"tags": [
"x_refsource_MISC"
]
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
}
}
]
}
}
}