Contao discloses sensitive information in the front end search index
Description
Published to the GitHub Advisory Database
Aug 28, 2025
Reviewed
Aug 28, 2025
Published by the National Vulnerability Database
Aug 28, 2025
Last updated
Aug 28, 2025
Impact
Protected content elements that are rendered as fragments are indexed and become publicly available in the front end search.
Patches
Update to Contao 4.13.56, 5.3.38 or 5.6.1.
Workarounds
Disable the front end search.
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References