statamic/cms is vulnerable to Insufficient Verification of Data Authenticity
45
Medium Risk
Affected versions of this package rely solely on the presence of the Precognition-Validate-Only header to trigger validation-only behavior, without verifying that the request is actually a legitimate precognitive request. This allows an attacker to spoof the header and bypass normal validation and submission logic, potentially preventing required validation rules from executing or altering application flow.
You are affected if you are using a version that falls within the vulnerable range.
statamic/cms is vulnerable to Insufficient Verification of Data Authenticity in versions 4.38.0 - 6.15.0.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant