Junglewise Threat Intelligence

CVE-2025-25691: PrestaShop PHAR deserialization in theme import

CVE-2025-25691 · Severity: medium · CVSS 6.5 · Published 2025-07-30

Technologies: PrestaShop. Vendors: PrestaShop.

Executive brief

PrestaShop, a popular open-source e-commerce platform, contains a security vulnerability in its theme import feature. An attacker can exploit this flaw to execute unauthorized code on the server hosting the online store. This could lead to a full compromise of the website, including the theft of customer data or disruption of business operations.

Technical details

A PHAR (PHP Archive) deserialization vulnerability exists within the theme import functionality (/themes/import) of PrestaShop v8.2.0. The flaw is triggered when the application improperly handles untrusted data during a POST request, leading to insecure deserialization. An attacker can leverage this to achieve remote code execution (RCE) or command injection (CWE-77). The vulnerability is reachable over the network without requiring specific user interaction, though the CVSS assessment suggests limited impact on confidentiality and integrity despite the potential for code execution. A proof-of-concept exploit has been identified in third-party repositories.

Affected products

  • PrestaShop PrestaShop 8.2.0

Timeline

  • 2025-07-30: advisory: Initial NVD publication date

References

Related threats