Executive brief
Sylius, an open-source e-commerce platform, fails to properly validate payment actions in its Shop API, allowing customers to trigger unauthorized refunds on completed orders. An attacker with a customer's order token can submit arbitrary payment requests like refunds that payment gateways will execute, while Sylius incorrectly maintains the order as paid—resulting in direct financial loss to merchants.
Technical details
The Shop API endpoint does not restrict payment action submissions, allowing customers to request arbitrary payment operations including refunds via order tokens. Attackers can bypass authorization checks by submitting payment actions that payment gateways process while Sylius fails to synchronize the order state, resulting in funds being refunded while the merchant's records show the order as paid. The vulnerability affects Sylius before versions 2.1.16 and 2.2.9.
Affected products
- Sylius Sylius before 2.1.16 and 2.2.9
Timeline
- 2026-09-27: disclosed