Junglewise Threat Intelligence

CVE-2026-47345: TYPO3 html-sanitizer XSS bypass via incorrect namespace encoding

CVE-2026-47345 · Severity: medium · CVSS 4 · Published 2026-06-08

Vendors: Packagist, Typo3.

Executive brief

The TYPO3 HTML Sanitizer, a library used to clean and secure user-provided web content, contains a flaw in how it handles specific HTML attributes. An attacker could use this to bypass security filters and inject malicious scripts into web pages. If successful, this could lead to unauthorized actions being performed in the context of a user's session, such as stealing login tokens or redirecting users to malicious sites.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in typo3/html-sanitizer due to improper neutralization of namespace attributes during the HTML serialization process. The root cause is a failure to correctly encode these attributes, which allows an attacker to craft malicious payloads that bypass the sanitizer's intended security logic. The attack requires network access and low privileges, typically involving a victim interacting with a page containing the malicious input. This can result in a bypass of the library's XSS prevention mechanisms. The issue is fixed in version 2.3.2 by ensuring namespace attributes are properly encoded in the Serializer component.

Affected products

  • TYPO3 html-sanitizer < 2.3.2

Timeline

  • 2026-06-08: disclosed: Initial disclosure by TYPO3 and NVD publication
  • 2026-06-12: advisory: GitHub Advisory published

References

Related threats