Junglewise Threat Intelligence

CVE-2026-42458: OpenMage Magento LTS reflected XSS in Dataflow Profiles

CVE-2026-42458 · Severity: medium · CVSS 4 · Published 2026-05-15

Technologies: OpenMage, openmage/magento-lts (Packagist). Vendors: OpenMage, Packagist.

Executive brief

A security vulnerability exists in the administrative interface of OpenMage Magento LTS, an e-commerce platform. An attacker could trick an administrator into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the administrator's browser. This could lead to the theft of sensitive session cookies, account takeover, or unauthorized changes to the store's configuration.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in OpenMage Magento LTS versions up to 20.17.0. The vulnerability is located in the 'Dataflow - Profiles' section of the admin panel (System -> Import/Export -> Dataflow - Profiles). The application fails to properly sanitize the 'files' parameter in the URL when running a profile, allowing an attacker to inject arbitrary HTML or JavaScript. While the path is within the admin panel, the vulnerability is reflected, meaning an attacker could potentially target an authenticated administrator via a crafted URL. Successful exploitation can lead to session hijacking or unauthorized administrative actions. The issue is fixed in version 20.18.0.

Affected products

  • OpenMage Magento LTS (OpenMage) <= 20.17.0

Timeline

  • 2026-05-04: disclosed: Initial disclosure in OpenMage repository
  • 2026-05-06: advisory: GitHub Advisory published
  • 2026-05-15: patched: NVD publication and version 20.18.0 release confirmed

References

Related threats