CVE-2026-8727HIGHCVSS 0.0

TYPO3 Remote Code Execution in extension "Site Crawler" (crawler)

Published May 19, 2026·Updated Jun 29, 2026

Description

The TYPO3 Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's `unserialize()`. An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. This has been patched in versions 12.0.11 and 11.0.13.

Affected Packages (1)

tomasnorre/crawlerCOMPOSER
From 12.0.0
Fixed in 12.0.11

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free