Executive brief
Shopware, an open-source e-commerce platform, contains a security flaw in its Single Sign-On (SSO) login system. An attacker can create a malicious link that appears to be a legitimate part of the trusted store but instead redirects users to a fraudulent website or executes malicious scripts. This can be used in phishing campaigns to steal customer credentials or damage the brand's reputation by making the official site appear to host malicious content.
Technical details
An open redirect vulnerability exists in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is accessed without a valid SSO session state, the application incorrectly falls back to using the 'Referer' header as the redirect destination. The application fails to validate this header, allowing absolute URLs, external domains, and dangerous URI schemes like 'javascript:'. An attacker can exploit this by crafting a request with a malicious Referer header; the server will then respond with a 302 redirect and an HTML body containing a meta refresh tag pointing to the attacker-controlled location. This can be used for phishing or potentially Cross-Site Scripting (XSS) depending on how the client handles the 'javascript:' scheme in the Location header and HTML body. The issue is resolved in version 6.7.10.1.
Affected products
- Shopware shopware/core >= 6.7.3.0, < 6.7.10.1
- Shopware shopware/platform >= 6.7.3.0, < 6.7.10.1
Timeline
- 2026-05-19: patched: Security release v6.7.10.1 published.
- 2026-07-23: disclosed: CVE-2026-48012 published to NVD.