Executive brief
TYPO3 CMS, a popular content management system, contains a flaw in how it validates file paths. This allows administrative users to bypass security restrictions and access or create files in directories outside of the intended project folder. While this requires high-level access to exploit, it could lead to unauthorized access to sensitive system files or configuration data.
Technical details
A path traversal vulnerability exists in the TYPO3 File Abstraction Layer (FAL) due to a flawed path allowance check in 'GeneralUtility::isAllowedAbsPath()'. The function performed a plain string prefix comparison without verifying directory separator boundaries (e.g., treating '/var/www/html-other' as a valid subpath of '/var/www/html'). An authenticated administrator with access to FAL can exploit this to create file storage definitions pointing to arbitrary directories outside the project root. This allows for unauthorized read/write access to sensitive files on the underlying filesystem. The issue is resolved in versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, and 14.3.3 LTS.
Affected products
- TYPO3 cms-core < 10.4.57, 11.0.0-11.5.50, 12.0.0-12.4.45, 13.0.0-13.4.30, 14.0.0-14.3.2
Timeline
- 2026-06-09: advisory: Initial advisory published by TYPO3
- 2026-06-12: disclosed: GHSA published and reviewed
References
- https://github.com/TYPO3/typo3/security/advisories/GHSA-jf56-v8jc-jcc5
- https://github.com/TYPO3/typo3/commit/150a983a5d687cedcfc33bbe9c335d9a13fd05e5
- https://github.com/TYPO3/typo3/commit/44c2fa9807944136218a0842e3051c0a379a002d
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2026-49738.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2026-016