GHSA-wh92-6q6g-px7j
Magento Community Edition Improper Input Validation vulnerability
Details
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
2.4.6-p1No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
2.4.9-alpha1No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
2.4.7-beta1No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
2.4.8-beta1No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
No fixed version published yet for magento/community-edition (composer). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for magento/project-community-edition (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-54236[ADVISORY]
- https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397[WEB]
- https://github.com/magento/magento2[PACKAGE]
- https://helpx.adobe.com/security/products/magento/apsb25-88.html[WEB]
- https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magento[WEB]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54236[WEB]