Vulnerability in Sylius eCommerce Framework Exposes Payment Request Data
CVE-2026-53639
What is CVE-2026-53639?
The Sylius eCommerce Framework contains an access control vulnerability that affects specific API endpoints handling payment requests. The identified issue allows attackers to access payment request details without proper ownership verification. By exploiting this vulnerability, an unauthorized party can retrieve sensitive order information, including email addresses and totals, using a hash obtained through various means. Furthermore, attackers can manipulate the redirection paths in payment processes to redirect users to malicious sites. The flaw exists in certain versions and has been addressed in subsequent updates. To mitigate the risk, users are advised to apply the recommended patches or implement specific workarounds that enhance API endpoint protection.
Affected Version(s)
Sylius >= 2.0.0, < 2.0.18 < 2.0.0, 2.0.18
Sylius >= 2.1.0, < 2.1.15 < 2.1.0, 2.1.15
Sylius >= 2.2.0, < 2.2.6 < 2.2.0, 2.2.6
