CVE-2026-77129Disclosure

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects. Exploitation of this issue requires an authenticated backend account with edit access to the event registration plugin or backend module.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-25: 2Technical Details · 2026-08-25: 208-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-77129 The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the eve… https://www.cve.org/CVERecord?id=CVE-2026-77129 ----- Traducción: CVE-2026-77129 La … https://infoflow.cloud`

    Post summary

    The message alerts to CVE-2026-77129, describing how an extension incorrectly injects an email subject string into a Fluid template, posing a potential risk for backend users with edit access.

    0000033
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-77129 The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the eve… https://www.cve.org/CVERecord?id=CVE-2026-77129

    Post summary

    The text announces CVE‑2026‑77129, explaining that an editor‑configurable email subject string is unsafely passed into a Fluid template source, representing a potential injection flaw.

    00000641
    58.0K followersView on X

Explore more