CVE-2025-59018: Information Disclosure in Workspaces Module
Missing authorization checks in the Workspace Module of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke the corresponding AJAX backend route to disclose sensitive information without having access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59018?
CVE-2025-59018 has a critical severity rating due to the potential for sensitive information disclosure.
How do I fix CVE-2025-59018?
To fix CVE-2025-59018, update TYPO3 CMS to versions that are not affected by this vulnerability.
Who is affected by CVE-2025-59018?
Backend users of TYPO3 CMS versions 9.0.0 to 9.5.54, 10.0.0 to 10.4.53, 11.0.0 to 11.5.47, 12.0.0 to 12.4.36, and 13.0.0 to 13.4.17 are affected by CVE-2025-59018.
What types of information can be disclosed due to CVE-2025-59018?
CVE-2025-59018 allows for unauthorized access to sensitive information via AJAX backend routes.
Is there a workaround for CVE-2025-59018?
Currently, there are no officially recommended workarounds for CVE-2025-59018, and updating is the best course of action.