Summary
CVE-2026-47345 is a TYPO3 HTML Sanitizer issue where namespace attributes were not encoded correctly during HTML serialization. That allowed bypassing the cross-site scripting prevention mechanism before the patched sanitizer release.
Attribution
TYPO3’s primary advisory names Doyensec in collaboration with Claude and Anthropic Research in the reporter credit. The same public record links the issue to fixed package versions and remediation guidance.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.