{"id":"GHSA-jr8m-x4p7-p3v5","summary":"TYPO3 Remote Code Execution in extension \"Site Crawler\" (crawler)","details":"The TYPO3 Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's `unserialize()`. An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl via a Scheduler task. This has been patched in versions 12.0.11 and 11.0.13.","aliases":["CVE-2026-8727"],"modified":"2026-09-10T03:51:06.299859616Z","published":"2026-05-19T12:31:39Z","database_specific":{"nvd_published_at":"2026-05-19T10:16:25Z","cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-29T17:39:15Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8727"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/tomasnorre/crawler/CVE-2026-8727.yaml"},{"type":"PACKAGE","url":"https://github.com/tomasnorre/crawler"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-008"}],"affected":[{"package":{"name":"tomasnorre/crawler","ecosystem":"Packagist","purl":"pkg:composer/tomasnorre/crawler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.0.0"},{"fixed":"12.0.11"}]}],"versions":["12.0.0","12.0.1","12.0.10","12.0.2","12.0.3","12.0.4","12.0.5","12.0.6","12.0.7","12.0.8","12.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jr8m-x4p7-p3v5/GHSA-jr8m-x4p7-p3v5.json"}},{"package":{"name":"tomasnorre/crawler","ecosystem":"Packagist","purl":"pkg:composer/tomasnorre/crawler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.13"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3","11.0.0","11.0.1","11.0.10","11.0.11","11.0.12","11.0.2","11.0.3","11.0.4","11.0.5","11.0.6","11.0.7","11.0.8","11.0.9","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.2.0","5.2.1","6.0.0","6.1.0","6.1.1","6.1.2","6.2.0","6.3.0","6.3.1","6.3.2","6.4.0","6.4.1","6.5.0","6.6.0","6.6.1","6.6.2","6.6.3","6.6.4","6.6.5","6.7.0","6.7.1","6.7.2","6.7.3","6.7.4","9.0.0","9.0.1","9.0.2","9.0.3","9.1.0","9.1.1","9.1.2","9.1.3","9.1.4","9.1.5","9.2.0","9.2.1","9.2.2","9.2.3","9.2.4","9.2.5","9.2.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-jr8m-x4p7-p3v5/GHSA-jr8m-x4p7-p3v5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"}]}