Medium severityNVD Advisory· Published Aug 25, 2026· Updated Sep 28, 2026
CVE-2026-77139
CVE-2026-77139
Description
The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or delete .html files outside the configured template directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- TYPO3: 24 Vulnerabilities Disclosed, Including Critical RCE and Code Execution FlawsVypr Intelligence · Aug 25, 2026