Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-77136: Powermail form lets attackers read data and run code
CVE-2026-77136 · published 1 month ago
Summary
The Powermail form add‑on processes the sender name field without checking it. A person can submit specially crafted text that makes the server reveal its settings, source code, or even run commands. Update Powermail to the latest release or change the form so the sender name is not used as raw input.
What to do
- Update typo3 extension "powermail" to version 13.2.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| typo3 | extension "powermail" | < 13.2.1 |
Original advisory text
Server-Side Template Injection in extension "powermail" (powermail)
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is configured as the sender_name field, a common and default-adjacent Powermail configuration. No authentication or user interaction beyond a normal form submission is required. This vulnerability is reported to be actively exploited in the wild.
References
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published25 Aug 2026
Updated9 Oct 2026
First seen25 Aug 2026
Track software like this
Free during beta