Skip to content

cms

v6.18.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 23d API Development
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

api-rest cms composer-package content-management-system flat-file-cms flatfile
+12 more
flatfilecms graphql headless jamstack laravel laravel-cms laravel-package php php8 ssg statamic vuejs

ReleasePort's take

Light signal
editorial:auto 13d

Release v6.18.1 hardens remote URL validation for improved security.

Why it matters: Patch to v6.18.1 immediately if your environment uses remote URLs; the fix addresses a validated vulnerability in URL handling.

Summary

AI summary

Harden remote URL validation to prevent security vulnerabilities.

Changes in this release

Security High

Remote URL validation hardened against malicious inputs

Remote URL validation hardened against malicious inputs

Source: granite4.1:30b@2026-05-24-audit

Confidence: low

Bugfix Medium

Date fieldtype input stops disappearing with underscore locales

Date fieldtype input stops disappearing with underscore locales

Source: llm_adapter@2026-05-21

Confidence: high

Bugfix Medium

Remote URL validation strengthens security and robustness

Remote URL validation strengthens security and robustness

Source: llm_adapter@2026-05-21

Confidence: low

Bugfix Medium

Scheduled status badge displays correctly in dark mode

Scheduled status badge displays correctly in dark mode

Source: llm_adapter@2026-05-21

Confidence: low

Full changelog

What's fixed

  • Tone down scheduled status badge in dark mode #14641 by @jasonvarga
  • Fix date fieldtype input disappearing with underscore locales #14643 by @jasonvarga
  • Harden remote URL validation #14645 by @jasonvarga

Security Fixes

  • Harden remote URL validation — mitigates potential injection or open‑redirect attacks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cms

Get notified when new releases ship.

Sign up free

About cms

The core Laravel CMS Composer package

All releases →

Beta — feedback welcome: [email protected]