File Upload Vulnerability in Saleor E-commerce Platform
CVE-2026-23499

8.5HIGH

Key Information:

Vendor

Saleor

Status
Vendor
CVE Published:
21 January 2026

What is CVE-2026-23499?

Saleor, an e-commerce platform, contains a file upload vulnerability that allows authenticated staff users and Apps to upload arbitrary files, including potentially harmful HTML and SVG files with embedded JavaScript. If these files are served from the same domain as the Saleor dashboard, they can execute malicious scripts in the user's browser. This poses a risk particularly if the corresponding media is hosted on the same domain as the dashboard without strict controls. Malicious staff users could exploit this vulnerability to execute script injections targeting other staff members, leading to the potential theft of access and refresh tokens. Mitigation strategies include upgrading to patched versions and configuring servers to set the appropriate Content-Disposition header so that harmful files prompt downloads rather than execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

saleor >= 3.2.0, < 3.22.27 < 3.2.0, 3.22.27

saleor >= 3.1.0, < 3.21.43 < 3.1.0, 3.21.43

saleor >= 3.0.0, < 3.20.108 < 3.0.0, 3.20.108

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.