CVE-2026-77139: TYPO3 Extension Mask

Medium severity, CVSS 6.0. EPSS: 0.4% chance of exploitation in the next 30 days.

The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or delete .html files outside the configured template directory.

Affected products

  • TYPO3 Extension Mask: from 9.0.0, before 9.0.11 (fixed in 9.0.11); before 8.3.12 (fixed in 8.3.12)

Published 2026-08-25. Last modified 2026-09-28.