Executive brief
The TYPO3 Content Element Selector extension, which helps manage how content is displayed on websites, contains a critical security flaw. An attacker can use a specially crafted browser cookie to take complete control of the web server. This could lead to the theft of sensitive customer data, website defacement, or a total service outage.
Technical details
The TYPO3 'Content Element Selector' (ceselector) extension is vulnerable to PHP Object Injection leading to Remote Code Execution (RCE). The root cause is the unsafe use of the PHP unserialize() function on attacker-controlled data provided via a cookie. To successfully exploit this, the content element must be configured with 'Persistent Mode: Static' in the plugin settings. An unauthenticated remote attacker can supply a crafted serialized payload to execute arbitrary code on the server. The vulnerability is patched in versions 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
Affected products
- TYPO3 Content Element Selector (ceselector) < 3.0.3, >= 4.0.0 < 4.0.2, >= 5.0.0 < 5.0.1, >= 6.0.0 < 6.0.1
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-06-29: patched: Advisory updated with patch information
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D