Junglewise Threat Intelligence

CVE-2026-53637: Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contai

CVE-2026-53637 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius is an open-source e-commerce platform. A vulnerability in the cart management component allows users to modify or delete orders that have already been completed and paid for. This can lead to irreversible loss of customer order history and data corruption within the store's database.

Technical details

A vulnerability exists in the Sylius Cart FormComponent where the LiveComponent fails to verify the current state of an order before performing mutations. If a user has a cart page open while the order is completed in another session (e.g., by an admin or a separate payment tab), subsequent actions like clearing the cart, removing items, or changing quantities are executed against the finalized order. This occurs because the `hydrateResource` and action methods do not sufficiently validate that the order is still in a 'cart' state. An attacker can deliberately exploit this to corrupt order data or delete completed records from the database. Patches are available in versions 2.0.18, 2.1.15, and 2.2.6.

Affected products

  • Sylius Sylius/Sylius >= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6

Timeline

  • 2026-06-02: disclosed: Initial publication date
  • 2026-07-09: advisory: Advisory updated

References

Related threats