CVE-2026-46722 PUBLISHED

XML External Entity Injection in extension "Faceted Search" (ke_search)

Assigner: TYPO3
Reserved: 16.05.2026 Published: 19.05.2026 Updated: 19.05.2026

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 5.9

Product Status

Vendor TYPO3
Product Extension "Faceted Search"
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.1 (excl.)
  • affected from 6.0.0 to 6.6.1 (excl.)
  • affected from 0 to 5.6.2 (excl.)

Credits

  • Seungbin Yang reporter
  • Christian Bülter remediation developer

References

Problem Types

  • CWE-611 Improper Restriction of XML External Entity Reference CWE