Skip to content

[GHSA-7p36-fq2r-4h7r] Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed#8149

Open
astapc wants to merge 1 commit into
astapc/advisory-improvement-8149from
astapc-GHSA-7p36-fq2r-4h7r
Open

[GHSA-7p36-fq2r-4h7r] Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed#8149
astapc wants to merge 1 commit into
astapc/advisory-improvement-8149from
astapc-GHSA-7p36-fq2r-4h7r

Conversation

@astapc

@astapc astapc commented Jun 26, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
This is fixed with 11.5.19 which is only available for our LTS clients in the private repo https://github.com/pimcore/ee-pimcore/releases/tag/v11.5.19

Copilot AI review requested due to automatic review settings June 26, 2026 06:18
Copilot stopped work on behalf of astapc due to an error June 26, 2026 06:18
@github-actions github-actions Bot changed the base branch from main to astapc/advisory-improvement-8149 June 26, 2026 06:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the OSV advisory record for GHSA-7p36-fq2r-4h7r (Pimcore CMS Twig Sandbox bypass), adjusting the advisory metadata and severity scoring information.

Changes:

  • Updates the modified timestamp in the advisory.
  • Removes the CVSS_V3 severity entry, leaving only CVSS_V4.
Comments suppressed due to low confidence (1)

advisories/github-reviewed/2026/06/GHSA-7p36-fq2r-4h7r/GHSA-7p36-fq2r-4h7r.json:15

  • The PR description says it updates CVSS v3, but this change removes the CVSS v3 severity entry entirely (leaving only CVSS v4). If the intent is to update (not drop) CVSS v3, please keep a CVSS_V3 entry here; otherwise, adjust the PR description to match the change so reviewers/consumers aren’t misled.
  "severity": [
    {
      "type": "CVSS_V4",
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
    }

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants