Path Traversal Vulnerability in TYPO3 Mask Extension
CVE-2026-77139
6MEDIUM
What is CVE-2026-77139?
A path traversal vulnerability exists in the TYPO3 Mask extension, where the extension improperly validates user-supplied template element keys. An authenticated backend user with access to the Mask module could exploit this oversight to construct malicious file paths. This exploitation grants the ability to create or delete .html files outside the designated template directory, posing significant risks to file integrity and the overall security of the TYPO3 environment.
Affected Version(s)
Extension "Mask" 9.0.0 < 9.0.11
Extension "Mask" 0 < 8.3.12
