TYPO3 'Content Element Selector' Extension Under Investigation for RCE
The TYPO3 'Content Element Selector' extension is under investigation for a potential Remote Code Execution vulnerability. Users of this extension should assess their exposure and consider upgrading.
What happened
An early warning has been issued regarding a potential Remote Code Execution (RCE) vulnerability in the TYPO3 'Content Element Selector' extension. This vulnerability, tracked as GHSA-8X3J-439W-537C, appears to allow unauthenticated attackers to execute arbitrary code via PHP Object Injection by supplying a crafted serialized payload. The vulnerability has been patched in versions 3.0.3, 4.0.2, 5.0.1, and 6.0.1 of the 'composer/mmc/ceselector' package. Users are advised to upgrade to one of these versions to mitigate the risk. For more details, consult the primary sources.
How 0Day mitigates this
composer/mmc/ceselector is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.