### Problem Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. ### Solution Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described. ### Credits TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it. ### Resources * [TYPO3-CORE-SA-2026-010](https://typo3.org/security/advisory/typo3-core-sa-2026-010)
Update typo3/cms-core to 13.4.31; typo3/cms-core to 14.3.3; typo3/cms-indexed-search to 13.4.31; typo3/cms-indexed-search to 14.3.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTYPO3 CMS has Cross-Site Scripting in Indexed Search affects typo3/cms-core (composer), typo3/cms-core (composer), typo3/cms-indexed-search (composer), typo3/cms-indexed-search (composer). Severity is medium. ### Problem Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. ### Solution Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described. ### Credits TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it. ### Resources * [TYPO3-CORE-SA-2026-010](https://typo3.org/security/advisory/typo3-core-sa-2026-010)
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
### Problem Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. ### Solution Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described. ### Credits TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it. ### Resources * [TYPO3-CORE-SA-2026-010](https://typo3.org/security/advisory/typo3-core-sa-2026-010)
Update typo3/cms-core to 13.4.31; typo3/cms-core to 14.3.3; typo3/cms-indexed-search to 13.4.31; typo3/cms-indexed-search to 14.3.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanTYPO3 CMS has Cross-Site Scripting in Indexed Search affects typo3/cms-core (composer), typo3/cms-core (composer), typo3/cms-indexed-search (composer), typo3/cms-indexed-search (composer). Severity is medium. ### Problem Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site Scripting vulnerability. ### Solution Update to TYPO3 versions 13.4.31 LTS, 14.3.3 LTS that fix the problem described. ### Credits TYPO3 CMS thanks Jan Kahmen and Sanjay Singh Jhala for reporting this issue, and to TYPO3 core & security team member Oliver Hader for fixing it. ### Resources * [TYPO3-CORE-SA-2026-010](https://typo3.org/security/advisory/typo3-core-sa-2026-010)
AI coding agents often install or upgrade packages automatically in composer. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range |
|---|
| Fixed version |
|---|
| typo3/cms-corecomposer | >=13.0.0,<13.4.31 | 13.4.31 |
|---|---|---|
| typo3/cms-corecomposer | >=14.0.0,<14.3.3 | 14.3.3 |
| typo3/cms-indexed-searchcomposer | >=13.0.0,<13.4.31 | 13.4.31 |
| typo3/cms-indexed-searchcomposer | >=14.0.0,<14.3.3 | 14.3.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Fixed version |
|---|
| typo3/cms-corecomposer | >=13.0.0,<13.4.31 | 13.4.31 |
|---|---|---|
| typo3/cms-corecomposer | >=14.0.0,<14.3.3 | 14.3.3 |
| typo3/cms-indexed-searchcomposer | >=13.0.0,<13.4.31 | 13.4.31 |
| typo3/cms-indexed-searchcomposer | >=14.0.0,<14.3.3 | 14.3.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard