The TYPO3 "Content Element Selector" (ceselector) extension passes an attacker-controlled cookie directly to PHP's `unserialize()` without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with `Persistent Mode: Static` in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
Update mmc/ceselector to 6.0.1; mmc/ceselector to 5.0.1; mmc/ceselector to 4.0.2; mmc/ceselector to 3.0.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTYPO3 Remote Code Execution in extension "Content Element Selector" (ceselector) affects mmc/ceselector (composer), mmc/ceselector (composer), mmc/ceselector (composer), mmc/ceselector (composer). Severity is critical. The TYPO3 "Content Element Selector" (ceselector) extension passes an attacker-controlled cookie directly to PHP's `unserialize()` without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with `Persistent Mode: Static` in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| mmc/ceselector |
The TYPO3 "Content Element Selector" (ceselector) extension passes an attacker-controlled cookie directly to PHP's `unserialize()` without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with `Persistent Mode: Static` in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
Update mmc/ceselector to 6.0.1; mmc/ceselector to 5.0.1; mmc/ceselector to 4.0.2; mmc/ceselector to 3.0.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTYPO3 Remote Code Execution in extension "Content Element Selector" (ceselector) affects mmc/ceselector (composer), mmc/ceselector (composer), mmc/ceselector (composer), mmc/ceselector (composer). Severity is critical. The TYPO3 "Content Element Selector" (ceselector) extension passes an attacker-controlled cookie directly to PHP's `unserialize()` without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation requires the content element to be configured with `Persistent Mode: Static` in the plugin settings. This has been patched in version 3.0.3, 4.0.2, 5.0.1, and 6.0.1.
AI coding agents often install or upgrade packages automatically in composer. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| mmc/ceselector |
| >=6.0.0,<6.0.1 |
| 6.0.1 |
| mmc/ceselectorcomposer | >=5.0.0,<5.0.1 | 5.0.1 |
|---|
| mmc/ceselectorcomposer | >=4.0.0,<4.0.2 | 4.0.2 |
|---|
| mmc/ceselectorcomposer | <3.0.3 | 3.0.3 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=6.0.0,<6.0.1 |
| 6.0.1 |
| mmc/ceselectorcomposer | >=5.0.0,<5.0.1 | 5.0.1 |
|---|
| mmc/ceselectorcomposer | >=4.0.0,<4.0.2 | 4.0.2 |
|---|
| mmc/ceselectorcomposer | <3.0.3 | 3.0.3 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard