Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jr8m-x4p7-p3v5 | TYPO3 Remote Code Execution in extension "Site Crawler" (crawler) |
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-008 |
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typo3
Typo3 extension "site Crawler" |
|
| Vendors & Products |
Typo3
Typo3 extension "site Crawler" |
Tue, 19 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. | |
| Title | Remote Code Execution in extension "Site Crawler" (crawler) | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-05-19T13:25:34.994Z
Reserved: 2026-05-16T09:55:33.916Z
Link: CVE-2026-8727
Updated: 2026-05-19T13:25:31.426Z
Status : Deferred
Published: 2026-05-19T10:16:25.747
Modified: 2026-06-17T11:04:20.503
Link: CVE-2026-8727
No data.
OpenCVE Enrichment
Updated: 2026-05-20T10:39:40Z
Github GHSA