PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77139 TYPO3 CVE debrief

The TYPO3 Extension 'Mask' is vulnerable to a path traversal attack. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or delete .html files outside the configured template directory. This vulnerability allows an attacker to potentially disrupt website functionality or integrity. Defenders should verify their exposure, restrict access to the Mask module, and prioritize patching or updating the extension. The CVE record and NVD entry provide details on the vulnerability, but further verification is required to determine the scope of affected versions and potential impact.

Vendor
TYPO3
Product
Extension "Mask"
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

Administrators and users of TYPO3 Extension 'Mask' should assess their exposure and take necessary actions to prevent exploitation. This includes verifying the version of the extension being used, restricting access to the Mask module, and monitoring for suspicious activity. Additionally, defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

The TYPO3 Extension 'Mask' vulnerability allows an authenticated user to create or delete files outside the template directory, potentially disrupting website functionality. Defenders should verify their exposure, restrict access to the Mask module, and prioritize patching or updating the extension.

  • Potential creation or deletion of .html files outside the configured template directory.
  • Possible disruption of website functionality or integrity.
  • Need for verification of affected versions and scope of impact.
  • Priority for updating or patching the vulnerable extension.

Technical summary

The TYPO3 Extension 'Mask' fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. This allows an authenticated backend user with access to the Mask module to supply a key containing path traversal sequences to create or delete .html files outside the configured template directory. The vulnerability is considered to be of medium severity, with a CVSS score of 6.0. The CVE record and NVD entry provide details on the vulnerability, but further verification is required to determine the scope of affected versions and potential impact.

Defensive priority

Medium

Recommended defensive actions

  • Verify the version of TYPO3 Extension 'Mask' being used and check if it is vulnerable.
  • Restrict access to the Mask module to trusted users only.
  • Monitor for suspicious activity related to .html file creation or deletion outside the configured template directory.
  • Implement additional security measures to prevent path traversal attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and potential impact requires further verification from official sources. Defenders should verify their exposure by reviewing the official advisory and CVE record, and checking for any additional information from the vendor or other trusted sources. The vulnerability is considered to be of medium severity, with a CVSS score of 6.0. The CVE record was published on 2026-08-25T09:17:34.647Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77139 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77139

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77139 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77139

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-017

    f4fb688c-4412-4426-b4b8-421ecf27b14a

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.