TYPO3 Faceted Search Extension XML External Entity Injection Vulnerability

Vulnerability

A vulnerability in the TYPO3 extension 'Faceted Search' (ke_search) allows for XML External Entity (XXE) injection. The issue arises because the OOXML parser in the file indexer does not disable external entity resolution. This flaw enables a crafted xlsx or pptx document placed in an indexed directory to read local files or make outbound HTTP requests, with the retrieved content being added to the search index. Additionally, the file indexer's directory path normalization is inadequate, permitting path traversal exploitation to access arbitrary server files.

Impact

Exploitation of this vulnerability could lead to unauthorized reading of local files or execution of outbound HTTP requests, with potentially sensitive content being indexed and made searchable.

Remediation

Users are advised to update to version 7.0.1, 6.6.1, or 5.6.2, available through the TYPO3 Extension Manager, Packagist, or directly from the TYPO3 Extensions Repository.

Added: May 19, 2026, 10:22 AM
Updated: May 19, 2026, 10:22 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
3.1
exploitability
5.4
remediation
3.1
relevance
8.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.