Executive brief
A vulnerability exists in the ke_search extension for TYPO3, which provides faceted full-text search capabilities. By placing a specially crafted document (such as an Excel or PowerPoint file) in a directory indexed by the system, an attacker can trick the server into revealing sensitive local files or making unauthorized web requests. This could lead to the exposure of internal configuration data or other private information through the search results.
Technical details
The TYPO3 faceted fulltext search extension (ke_search) contains an XML External Entity (XXE) vulnerability within its OOXML parsing logic used by the file indexer. The component fails to disable external entity resolution when processing Office documents like .xlsx or .pptx. An attacker with the ability to place files in an indexed directory (requiring high privileges) can exploit this to read local system files or perform Server-Side Request Forgery (SSRF). The retrieved content is subsequently written to the search index, where it may be viewed. The issue is fixed in versions 7.0.1, 6.6.1, 5.6.2, and 4.6.7.
Affected products
- tpwd ke_search >= 7.0.0, < 7.0.1; >= 6.0.0, < 6.6.1; >= 5.0.0, < 5.6.2; < 4.6.7
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D