CVE-2025-59016: Information Disclosure via File Abstraction Layer
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59016?
CVE-2025-59016 is considered a medium severity vulnerability due to its potential to disclose sensitive information.
How do I fix CVE-2025-59016?
To fix CVE-2025-59016, upgrade to TYPO3 CMS version 9.5.55, 10.4.54, 11.5.48, 12.4.37, or 13.4.18.
Who is affected by CVE-2025-59016?
CVE-2025-59016 affects TYPO3 CMS users running versions 9.0.0 to 9.5.54, 10.0.0 to 10.4.53, 11.0.0 to 11.5.47, 12.0.0 to 12.4.36, and 13.0.0 to 13.4.17.
What type of information can be disclosed due to CVE-2025-59016?
CVE-2025-59016 allows backend users to disclose full file paths through error messages during failed low-level file-system operations.
When was CVE-2025-59016 disclosed?
CVE-2025-59016 was disclosed in 2025 as part of a security advisory for TYPO3.