All findings

CVE-2026-47345 medium

TYPO3 credits Doyensec and Claude for HTML Sanitizer XSS

TYPO3's June 2026 advisory credits IPC Labs and Doyensec in collaboration with Claude and Anthropic Research for CVE-2026-47345, an HTML Sanitizer namespace-attribute XSS bypass.

Bug class
Cross-site scripting sanitizer bypass
Affected codebase
TYPO3 HTML Sanitizer
Credited system
Claude / Anthropic Research
Disclosed
June 8, 2026
Attribution
Direct source attribution
Severity
medium
Source status: TYPO3's advisory directly credits IPC Labs and Doyensec in collaboration with Claude and Anthropic Research. GitHub and CVE mirrors corroborate CVE-2026-47345 / GHSA-p5j5-4j3q-8mq8 and the patched version.

Summary

CVE-2026-47345 is a TYPO3 HTML Sanitizer issue where namespace attributes were not encoded correctly during HTML serialization. That allowed bypassing the cross-site scripting prevention mechanism before the patched sanitizer release.

Attribution

TYPO3’s primary advisory names Doyensec in collaboration with Claude and Anthropic Research in the reporter credit. The same public record links the issue to fixed package versions and remediation guidance.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.