HIGH7.2
GHSA-7cw6-7h3h-v8pf
Shopware Has Improper Control of Generation of Code in Twig rendered views
Quick fix
GHSA-7cw6-7h3h-v8pf — shopware/shopware: upgrade to the fixed version with the command below.
composer require shopware/shopware:^6.7.6.1Details
### Impact We fixed with [CVE-2023-2017](https://github.com/advisories/GHSA-7v2v-9rm4-7m8f) Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override
### Patches Patched in 6.7.6.1
### Workarounds Install the security plugin
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/shopware/shopware
Introduced in:
6.7.0.0Fixed in: 6.7.6.1Fix
composer require shopware/shopware:^6.7.6.1Packagist/shopware/core
Introduced in:
6.7.0.0Fixed in: 6.7.6.1Fix
composer require shopware/core:^6.7.6.1References
- https://github.com/shopware/shopware/security/advisories/GHSA-7cw6-7h3h-v8pf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23498[ADVISORY]
- https://github.com/shopware/shopware/commit/3966b05590e29432b8485ba47b4fcd14dd0b8475[WEB]
- https://github.com/advisories/GHSA-7v2v-9rm4-7m8f[ADVISORY]
- https://github.com/shopware/shopware[PACKAGE]