Junglewise Threat Intelligence

CVE-2026-42207: OpenMage Magento LTS open redirect in stockAction controller

CVE-2026-42207 · Severity: medium · CVSS 6.1 · Published 2026-05-15

Technologies: OpenMage, openmage/magento-lts (Packagist). Vendors: OpenMage, Packagist.

Executive brief

OpenMage Magento LTS is an e-commerce platform used to manage online stores. A vulnerability in the product stock notification system allows attackers to redirect logged-in customers to malicious external websites. This can be used to facilitate phishing attacks, steal login credentials, or distribute malware by leveraging the trust customers have in the store's legitimate domain.

Technical details

An open redirect vulnerability exists in Mage_ProductAlert_AddController::stockAction() due to insufficient validation of the 'uenc' parameter. When a request is made with a non-existent 'product_id', the controller fails to call _isUrlInternal() before passing the 'uenc' value to _redirectUrl(). An attacker can craft a malicious URL that, when clicked by a logged-in customer, triggers a 302 redirect to an arbitrary destination. This vulnerability is particularly effective for phishing or stealing OAuth tokens if social login is implemented. The issue is patched in version 20.18.0.

Affected products

  • OpenMage magento-lts <= 20.17.0

Timeline

  • 2026-05-04: disclosed
  • 2026-05-05: advisory: GitHub Advisory published
  • 2026-05-15: other: NVD publication

References

Related threats