{"id":"GHSA-mfqj-cqv3-h7xw","summary":"TYPO3 CMS - Unrestricted File Upload in Form Framework","details":"### Problem\nUsers were able to upload files with arbitrary MIME types to forms using _FileUpload_ or _ImageUpload_ elements with _allowedMimeTypes_ configured - uploading PHP files was **not** possible. The restriction was not enforced server-side because the _MimeTypeValidator_ was registered during form building before concrete form definition properties were applied, resulting in the validator never being added to the processing pipeline.\n\n### Solution\nUpdate to TYPO3 version 14.3.5 LTS that fixes the problem described.\n\n### Credits\nThanks to Sébastien Convers for reporting this issue, and to Josua Vogel and Oliver Hader for fixing it.","aliases":["CVE-2026-15305"],"modified":"2026-08-31T20:25:45.219133Z","published":"2026-08-31T19:53:59Z","database_specific":{"cwe_ids":["CWE-351"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-31T19:53:59Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/TYPO3/typo3/security/advisories/GHSA-mfqj-cqv3-h7xw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15305"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/817ad41cc9dd28aac0fc4d0fe16fc25d46dd554a"},{"type":"WEB","url":"https://github.com/TYPO3/typo3/commit/cfda21050398eb145211a4fa6f9988f10e43e10b"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-form/CVE-2026-15305.yaml"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://news.typo3.com/security/advisory/typo3-core-sa-2026-020"},{"type":"WEB","url":"https://typo3.org/security/advisory/typo3-core-sa-2026-020"}],"affected":[{"package":{"name":"typo3/cms-form","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-form"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.2.0"},{"fixed":"14.3.5"}]}],"versions":["v14.2.0","v14.3.0","v14.3.1","v14.3.2","v14.3.3","v14.3.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 14.3.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mfqj-cqv3-h7xw/GHSA-mfqj-cqv3-h7xw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}