VDB
Sign up
HIGH8.8

PYSEC-2026-916

Mirumee Saleor CSRF Protection Disabled

Quick fix

PYSEC-2026-916 — saleor: upgrade to the fixed version with the command below.

pip install --upgrade 'saleor>=2.8.0'

Details

In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/saleor
Introduced in: 2.7.0Fixed in: 2.8.0
Fixpip install --upgrade 'saleor>=2.8.0'

References