Insecure Deserialization Vulnerability in TrueLayer Magento 2 Plugin
CVE-2026-103831
What is CVE-2026-103831?
The Psr16CacheAdapter component in the TrueLayer Magento 2 Plugin contains a vulnerability due to the insecure use of PHP's native unserialize() function. This flaw allows an attacker with write access to the cache backend—commonly Redis or Memcached—to inject manipulated data, potentially triggering the deserialization of specially crafted PHP objects. This exploitation may lead to arbitrary code execution based on gadget strings present in the application environment. This vulnerability emphasizes the necessity for robust input validation and restricted handling of deserialized data to prevent unauthorized access and code execution risks.
Affected Version(s)
TrueLayer Magento 2 Plugin versions 2.4.0 through 2.4.2.
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
