Impact
TYPO3 and GitHub advisories describe CVE-2026-46725 / GHSA-8x3j-439w-537c as a critical insecure-deserialization issue in the third-party Content Element Selector extension, published as the Composer package mmc/ceselector [S1][S2]. A vulnerable deployment can expose remote-code-execution risk when the affected extension version, TYPO3 runtime, content element configuration, and request path line up. The TYPO3 advisory notes that exploitation requires Persistent Mode: Static [S2].
Real customer impact depends on the package version that is actually deployed, whether the extension is enabled, whether the relevant plugin setting is in use, and whether untrusted traffic can reach the vulnerable flow. Treat stale Composer evidence as urgent upgrade and runtime verification work, not as proof that a live site is exploitable.
Affected package evidence
The reviewed GitHub Advisory, TYPO3 advisory, OSV entry, and FriendsOfPHP advisory all identify mmc/ceselector as the affected Packagist/Composer package [S1][S2][S4][S5]. The affected release branches are 6.0.0, 5.0.0, 4.0.0 through 4.0.1, and 3.0.2 or older. Fixed releases are 6.0.1, 5.0.1, 4.0.2, and 3.0.3 [S1][S2][S4][S5]. NVD tracks the same CVE with CWE-502 and a critical CVSS v4.0 CNA score [S3].
Remediation
Upgrade mmc/ceselector to the fixed release for the active branch: 6.0.1, 5.0.1, 4.0.2, or 3.0.3 [S1][S2]. Regenerate and commit composer.lock, rebuild or redeploy the TYPO3/PHP runtime, and verify the deployed Composer tree plus the TYPO3 extension manager/runtime version. If the TYPO3 site is managed outside the scanned repository, assign the package, image, host, and extension-setting verification to that owner.
While rollout is in progress, review ceselector content elements and plugin settings, especially Persistent Mode: Static, and disable or restrict the extension where the fixed package cannot be deployed promptly [S2]. Use normal TYPO3 smoke tests and configuration review for validation.
How FixVibe covers it
FixVibe's GitHub repo scans flag composer.lock entries and composer.json constraints that resolve to mmc/ceselector versions affected by CVE-2026-46725 / GHSA-8x3j-439w-537c, with the file, line, version and remediation guidance.
