Executive brief
The TYPO3 Site Crawler extension, used to automate page indexing and cache management, is vulnerable to a flaw that allows an attacker to take full control of the web server. By controlling a website that the crawler visits, an attacker can execute malicious code on the TYPO3 server. This could lead to total data theft, service disruption, or unauthorized access to internal systems.
Technical details
The TYPO3 Crawler (crawler) extension is vulnerable to insecure deserialization (CWE-502). The extension retrieves the 'X-T3Crawler-Meta' response header from crawled URLs and passes it directly to PHP's unserialize() function without validation. An attacker who can control the content of a crawled endpoint can provide a malicious serialized payload to achieve Remote Code Execution (RCE). Exploitation is complex as it requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. The vulnerability is patched in versions 12.0.11 and 11.0.13.
Affected products
- TYPO3 crawler >= 12.0.0, < 12.0.11
- TYPO3 crawler < 11.0.13
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched
References
- https://api.github.com/users/eliashaeussler
- https://github.com/eliashaeussler
- https://api.github.com/users/eliashaeussler/gists%7B/gist_id%7D
- https://api.github.com/users/eliashaeussler/repos
- https://avatars.githubusercontent.com/u/16313625?v=4
- https://api.github.com/users/eliashaeussler/events%7B/privacy%7D