Executive brief
The ke_search extension for TYPO3, which provides search functionality for websites, contains a security flaw in its file indexing component. An authorized administrative user could exploit this to access and index sensitive files from the server's internal file system that should normally be restricted. This could lead to the exposure of confidential system data or configuration files through the website's search results.
Technical details
A path traversal vulnerability exists in the file indexer component of the TYPO3 ke_search extension. The root cause is a failure to normalize directory paths in the indexer configuration, allowing the use of traversal sequences (e.g., ../). An attacker with backend privileges to edit indexer configurations can leverage this to index documents from arbitrary locations on the server's filesystem. This results in unauthorized information disclosure as the contents of these files become searchable. The issue is fixed in versions 7.0.1, 6.6.1, 5.6.2, and 4.6.7.
Affected products
- tpwd ke_search < 4.6.7, >= 5.0.0 < 5.6.2, >= 6.0.0 < 6.6.1, >= 7.0.0 < 7.0.1
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-06-29: patched: Advisory updated with patch information
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D