{"id":"CVE-2026-8727","summary":"Remote Code Execution in extension \"Site Crawler\" (crawler)","details":"The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task.","aliases":["GHSA-jr8m-x4p7-p3v5"],"modified":"2026-07-15T01:48:52.132554811Z","published":"2026-05-19T09:16:33.677Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8727.json","cna_assigner":"TYPO3","cwe_ids":["CWE-502"]},"references":[{"type":"WEB","url":"https://packagist.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8727.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8727"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-008"},{"type":"PACKAGE","url":"https://github.com/tomasnorre/crawler"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tomasnorre/crawler","events":[{"introduced":"c25e671526f547f65b69adfce335834c66f54b24"},{"fixed":"5ab06b6f5326d6bb20dbe46e7925e9db490036bd"},{"introduced":"0"},{"fixed":"f9a1d646e88c2b18248031578758a5a938ce6c8f"}],"database_specific":{"extracted_events":[{"introduced":"12.0.0"},{"fixed":"12.0.11"},{"introduced":"0"},{"fixed":"11.0.13"}],"source":"AFFECTED_FIELD"}}],"versions":["11.0.12","12.0.10","12.0.9","12.0.8","11.0.11","12.0.7","12.0.6","12.0.5","11.0.10","12.0.4","11.0.9","12.0.3","12.0.2","12.0.1","11.0.8","12.0.0","11.0.7","11.0.6","11.0.5","11.0.4","11.0.3","11.0.2","11.0.1","11.0.0","10.0.3","10.0.2","10.0.1","10.0.0","9.2.5","9.2.4","9.2.3","9.2.2","9.2.1","9.2.0","9.1.5","9.1.4","9.1.3","9.1.2","9.1.1","9.1.0","9.0.3","9.0.2","9.0.1","9.0.0","6.1.2","6.1.1","6.1.0","6.0.0","5.2.1","5.2.0","5.1.4","5.1.3","5.1.2","5.1.1","5.0.9","5.0.8","5.0.7","5.0.6","5.0.5","5.0.4","5.0.3","4.1.0","5.0.2","5.0.1","5.0.0","4.0.0","3.6.2","3.6.1","3.6.0","3.5.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8727.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"}]}