PT-2026-41867 · Typo3 · Crawler Extension
Roman Hergenreder
·
Published
2026-05-19
·
Updated
2026-05-19
·
CVE-2026-8727
CVSS v4.0
7.1
High
| Vector | AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
TYPO3 Crawler extension (affected versions not specified)
Description
The Crawler extension is subject to Remote Code Execution via PHP Object Injection. This occurs because the extension passes the "X-T3Crawler-Meta" response header from crawled URLs directly to the PHP
unserialize() function. An attacker who controls a crawled endpoint can inject arbitrary serialized PHP objects to execute code on the server. Exploitation requires administrative privileges to configure a crawler-enabled page and trigger the crawl through a Scheduler task.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crawler Extension