Description
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 2.3.2
Credits
Doyensec in collaboration with Claude and Anthropic Research
Benjamin Franzke
References
typo3.org/security/advisory/typo3-core-sa-2026-006
github.com/...ommit/8b5d0be44ded457ca993ec9ca93d859941c63764