{"id":"CVE-2025-59013","aliases":["GHSA-72jf-5fg5-3cw3"],"url":"https://o3.security/vulnerability/CVE-2025-59013","summary":"Open Redirect in TYPO3 CMS","details":"An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL.","published":"2025-09-09T09:00:23.176Z","modified":"2026-08-27T03:30:48.529382876Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.37"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.37"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.37"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"12.4.37"},{"ecosystem":"Packagist","name":"typo3/cms-core","fixedVersion":"13.4.18"}],"fix":null,"references":[{"type":"WEB","url":"https://packagist.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59013.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59013"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-core-sa-2025-017"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:30:48.529382876Z"}}