{"id":"GHSA-8x3j-439w-537c","summary":"TYPO3 Remote Code Execution in extension \"Content Element Selector\" (ceselector)","details":"The TYPO3 \"Content Element Selector\" (ceselector) extension passes an attacker-controlled cookie directly to PHP's `unserialize()` without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with `Persistent Mode: Static` in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.","aliases":["CVE-2026-46725"],"modified":"2026-09-10T03:50:11.689803732Z","published":"2026-05-19T12:31:39Z","database_specific":{"github_reviewed_at":"2026-06-29T17:30:20Z","nvd_published_at":"2026-05-19T10:16:25Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46725"},{"type":"PACKAGE","url":"https://bitbucket.org/thismaechler/typo3-ext-ceselector"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/mmc/ceselector/CVE-2026-46725.yaml"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-013"}],"affected":[{"package":{"name":"mmc/ceselector","ecosystem":"Packagist","purl":"pkg:composer/mmc/ceselector"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.1"}]}],"versions":["6.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-8x3j-439w-537c/GHSA-8x3j-439w-537c.json"}},{"package":{"name":"mmc/ceselector","ecosystem":"Packagist","purl":"pkg:composer/mmc/ceselector"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.1"}]}],"versions":["5.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-8x3j-439w-537c/GHSA-8x3j-439w-537c.json"}},{"package":{"name":"mmc/ceselector","ecosystem":"Packagist","purl":"pkg:composer/mmc/ceselector"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.2"}]}],"versions":["4.0.0","4.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-8x3j-439w-537c/GHSA-8x3j-439w-537c.json"}},{"package":{"name":"mmc/ceselector","ecosystem":"Packagist","purl":"pkg:composer/mmc/ceselector"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.3"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","3.0.0","3.0.1","3.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-8x3j-439w-537c/GHSA-8x3j-439w-537c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}