GHSA-r54v-qq87-px5r
Craft Commerce hasVariant/hasProduct Blind SQL Injection
Quick fix
GHSA-r54v-qq87-px5r — craftcms/commerce: upgrade to the fixed version with the command below.
composer require craftcms/commerce:^5.6.0Details
## Overview
Craft Commerce’s `ProductQuery::hasVariant` and `VariantQuery::hasProduct` properties bypass the `unset()` blocklist added to `ElementIndexesController` in GHSA-2453-mppf-46cj.
The blocklist only strips top-level Yii2 Query properties (`where`, `orderBy`, etc.), but `hasVariant` and `hasProduct` pass through untouched. Internally, these properties call `Craft::configure()` on a subquery without sanitization, re-introducing SQL injection via `criteria[hasVariant][where]=INJECTED_SQL`.
An authenticated control panel user can perform boolean-based blind SQL injection through the patched `ElementIndexesController` and extract arbitrary database contents.
## Impact
* Full database read access via blind SQL injection * Privilege escalation via security key extraction → forged admin sessions
## Prerequisites * Authenticated control panel user * Commerce plugin installed * Products with variants in the database
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0Fixed in: 5.6.0composer require craftcms/commerce:^5.6.0References
- https://github.com/craftcms/commerce/security/advisories/GHSA-r54v-qq87-px5r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32272[ADVISORY]
- https://github.com/craftcms/commerce/pull/4232[WEB]
- https://github.com/advisories/GHSA-2453-mppf-46cj[ADVISORY]
- https://github.com/craftcms/commerce[PACKAGE]
- https://github.com/craftcms/commerce/releases/tag/5.6.0[WEB]