Vulnerability DatabaseGHSA-g4xv-r3qw-v3q2

GHSA-g4xv-r3qw-v3q2
PHP vulnerability analysis and mitigation

Overview

A security vulnerability was identified in TYPO3 Neos that allows unauthorized access to internal workspaces. The issue affects Neos versions from 2.3 through 4.3, with the disclosure date of June 17, 2019. The vulnerability enables unauthenticated users to view content in internal workspaces, which are non-public workspaces without specific owners (Neos Blog).

Technical details

The vulnerability allows unauthorized access to internal workspaces through a specific URL format: https://domain/path/to/page.html@workspace-name. The issue has been assigned a high severity rating and affects multiple version ranges including 2.3.0-2.3.99, 3.0.0-3.0.20, 3.1.0-3.1.18, 3.2.0-3.2.14, 3.3.0-3.3.23, 4.0.0-4.0.17, 4.1.0-4.1.16, 4.2.0-4.2.12, and 4.3.0-4.3.3. The suggested CVSS score is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C/CR:L/IR:L/AR:L (Neos Blog, GitHub Advisory).

Impact

The vulnerability allows read-only access to internal workspaces. While the issue is significant, its impact is somewhat limited as there are no default internal workspaces, and the vulnerability only affects user-created workspaces. Additionally, an attacker would need to know the specific workspace name, which includes a hash unique to each project (GitHub Advisory).

Exploitability

Exploitation requires knowledge of the workspace name including its hash, which is not trivially discoverable. However, it could potentially be obtained through brute force attempts or educated guesses. The vulnerability can be exploited by accessing a specific URL format that includes the workspace name (Neos Blog).

Mitigation and workarounds

The vulnerability has been patched in versions 2.3.99, 3.0.20, 3.1.18, 3.2.14, 3.3.23, 4.0.17, 4.1.16, 4.2.12, and 4.3.3. Users are advised to update both neos/neos and neos/contentrepository packages to the newest bugfix versions. For Neos 2.3 users, immediate update is strongly recommended (GitHub Advisory, Neos Blog).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56825HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-49992MEDIUM6.3
  • PHP logoPHP
  • kimai/kimai
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management