VDB
Sign up
HIGH

GHSA-3v8v-4wg6-r7qh

TYPO3 CMS: Destructive Actions on File Mount Folders

Quick fix

GHSA-3v8v-4wg6-r7qh — typo3/cms-core: upgrade to the fixed version with the command below.

composer require typo3/cms-core:^10.4.57

Details

### Problem Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on folders representing the root of an active file mount due to missing authorization restrictions.

### Solution Update to TYPO3 versions 10.4.57 ELTS, 11.5.51 ELTS, 12.4.46 ELTS, 13.4.31 LTS, 14.3.3 LTS that fix the problem described.

### Credits TYPO3 CMS thanks Arne Uplegger for reporting this issue, and TYPO3 security team member Elias Häußler for fixing it.

### Resources * [TYPO3-CORE-SA-2026-007](https://typo3.org/security/advisory/typo3-core-sa-2026-007)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-core
Introduced in: 0Fixed in: 10.4.57
Fixcomposer require typo3/cms-core:^10.4.57
Packagist/typo3/cms-core
Introduced in: 11.0.0Fixed in: 11.5.51
Fixcomposer require typo3/cms-core:^11.5.51
Packagist/typo3/cms-core
Introduced in: 12.0.0Fixed in: 12.4.46
Fixcomposer require typo3/cms-core:^12.4.46
Packagist/typo3/cms-core
Introduced in: 13.0.0Fixed in: 13.4.31
Fixcomposer require typo3/cms-core:^13.4.31
Packagist/typo3/cms-core
Introduced in: 14.0.0Fixed in: 14.3.3
Fixcomposer require typo3/cms-core:^14.3.3

References