Path Traversal Vulnerability in TYPO3 Mask Extension
CVE-2026-77139

6MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-77139?

A path traversal vulnerability exists in the TYPO3 Mask extension, where the extension improperly validates user-supplied template element keys. An authenticated backend user with access to the Mask module could exploit this oversight to construct malicious file paths. This exploitation grants the ability to create or delete .html files outside the designated template directory, posing significant risks to file integrity and the overall security of the TYPO3 environment.

Affected Version(s)

Extension "Mask" 9.0.0 < 9.0.11

Extension "Mask" 0 < 8.3.12

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Nikita Hovratov
.