{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.0.471"
              },
              {
                "introduced": "1.1.0"
              },
              {
                "last_affected": "1.1.1"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "61e49d9e0b5f7e5323353f254d4ff12905bbe573"
            },
            {
              "introduced": "6389554935644bfbb15db5fcd0ce4db6cbe3d103"
            },
            {
              "last_affected": "24d95a208bf4a0840d7b631a87ad1ce3fb4a5ed3"
            }
          ],
          "repo": "https://github.com/octobercms/october",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 \u0026 CVE-2020-15247. An authenticated backend user with the `cms.manage_pages`, `cms.manage_layouts`, or `cms.manage_partials` permissions who would **normally** not be permitted to provide PHP code to be executed by the CMS due to `cms.enableSafeMode` being enabled is able to write specific Twig code to escape the Twig sandbox and execute arbitrary PHP. This is not a problem for anyone that trusts their users with those permissions to normally write \u0026 manage PHP within the CMS by not having `cms.enableSafeMode` enabled, but would be a problem for anyone relying on `cms.enableSafeMode` to ensure that users with those permissions in production do not have access to write \u0026 execute arbitrary PHP. Issue has been patched in Build 472 (v1.0.472) and v1.1.2. As a workaround, apply https://github.com/octobercms/october/commit/f63519ff1e8d375df30deba63156a2fc97aa9ee7 to your installation manually if unable to upgrade to Build 472 or v1.1.2.",
  "id": "CVE-2021-21264",
  "modified": "2026-03-13T21:56:15.379901767Z",
  "published": "2021-05-03T16:15:07.510Z",
  "references": [
    {
      "type": "FIX",
      "url": "https://github.com/octobercms/october/security/advisories/GHSA-fcr8-6q7r-m4wg"
    }
  ],
  "related": [
    "GHSA-fcr8-6q7r-m4wg"
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ]
}