Skip to content

chore(deps): update dependency typo3/cms-core to v14 [security] - autoclosed - #29

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/packagist-typo3-cms-core-vulnerability
Closed

chore(deps): update dependency typo3/cms-core to v14 [security] - autoclosed#29
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/packagist-typo3-cms-core-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
typo3/cms-core (source) ^12.0 || ^13.0 -> ^14.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-59013

An open‑redirect vulnerability in GeneralUtility::sanitizeLocalUrl of TYPO3 CMS 9.0.0–9.5.54, 10.0.0–10.4.53, 11.0.0–11.5.47, 12.0.0–12.4.36, and 13.0.0–13.4.17 allows an attacker to redirect users to arbitrary external sites, enabling phishing attacks by supplying a manipulated, sanitized URL.

CVE-2025-59015

A deterministic three‑character prefix in the Password Generation component of TYPO3 CMS versions 12.0.0–12.4.36 and 13.0.0–13.4.17 reduces entropy, allowing attackers to carry out brute‑force attacks more quickly.

CVE-2025-59016

Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-system operations.


Release Notes

TYPO3-CMS/core (typo3/cms-core)

v14.0.0

Compare Source

v13.4.21

Compare Source

v13.4.20

Compare Source

v13.4.19

Compare Source

v13.4.18

Compare Source

v13.4.17

Compare Source

v13.4.16

Compare Source

v13.4.15

Compare Source

v13.4.14

Compare Source

v13.4.13

Compare Source

v13.4.12

Compare Source

v13.4.11

Compare Source

v13.4.10

Compare Source

v13.4.9

Compare Source

v13.4.8

Compare Source

v13.4.7

Compare Source

v13.4.6

Compare Source

v13.4.5

Compare Source

v13.4.4

Compare Source

v13.4.3

Compare Source

v13.4.2

Compare Source

v13.4.1

Compare Source

v13.4.0

Compare Source

v13.3.1

Compare Source

v13.3.0

Compare Source

v13.2.1

Compare Source

v13.2.0

Compare Source

v13.1.1

Compare Source

v13.1.0

Compare Source

v13.0.1

Compare Source

v13.0.0

Compare Source

v12.4.40

Compare Source

v12.4.39

Compare Source

v12.4.38

Compare Source

v12.4.37

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

| datasource | package        | from    | to     |
| ---------- | -------------- | ------- | ------ |
| packagist  | typo3/cms-core | 12.4.36 | 14.0.0 |
@renovate

renovate Bot commented Nov 26, 2025

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: composer.lock
Command failed: composer update typo3/cms-core:14.0.0 --with-dependencies --ignore-platform-req ext-intl --no-ansi --no-interaction --no-scripts --no-autoloader --no-plugins --minimal-changes
./composer.lock is present but ignored as the "lock" config option is disabled.
Cannot update only a partial set of packages without a lock file present. Run `composer update` to generate a lock file.

@coderabbitai

coderabbitai Bot commented Nov 26, 2025

Copy link
Copy Markdown

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (1)
  • chore(deps)

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate Bot changed the title chore(deps): update dependency typo3/cms-core to v14 [security] chore(deps): update dependency typo3/cms-core to v14 [security] - autoclosed Dec 22, 2025
@renovate renovate Bot closed this Dec 22, 2025
@renovate
renovate Bot deleted the renovate/packagist-typo3-cms-core-vulnerability branch December 22, 2025 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant