VDB
Sign up
MEDIUM5.3

PYSEC-2026-747

Missing Authentication for Critical Function in Saleor

Quick fix

PYSEC-2026-747 — saleor: upgrade to the fixed version with the command below.

pip install --upgrade 'saleor>=2.9.1'

Details

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/saleor
Introduced in: 2.0.0Fixed in: 2.9.1
Fixpip install --upgrade 'saleor>=2.9.1'

References