CVE-2025-59016 Details
Description
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.
A vulnerability allowing information disclosure has been identified in TYPO3 CMS versions 9.0.0 prior to 9.5.54, 10.0.0 prior to 10.4.53, 11.0.0 prior to 11.5.47, 12.0.0 prior to 12.4.36, and 13.0.0 prior to 13.4.17. This vulnerability arises from error messages in the File Abstraction Layer that unintentionally reveal full file paths. The issue occurs during certain low-level file-system operations that fail, disclosing sensitive information to backend users.
Users are advised to update to TYPO3 versions 9.5.55 ELTS, 10.4.54 ELTS, 11.5.48 ELTS, 12.4.37 LTS, or 13.4.18 LTS, all of which address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-core-sa-2025-020 | TYPO3 | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-209 | Generation of Error Message Containing Sensitive Information | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| typo3 typo3 | >= 9.0.0, < 9.5.55 >= 10.0.0, <= 10.4.54 >= 11.0.0, <= 11.5.48 >= 12.0.0, <= 12.4.37 >= 13.0.0, <= 13.4.18 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2025 | Initial Analysis | [email protected] |
| Sep 9, 2025 | New CVE Received | TYPO3 |