Description
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorized modification or deletion of previously completed orders
Action: Patch
AI Analysis

Impact

Sylius, an open source eCommerce framework built on Symfony, contains an improper workflow enforcement flaw in its cart FormComponent. When an order is completed but the cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to allow cart actions. This flaw permits an authenticated customer to modify or permanently delete an already completed order, directly compromising order integrity and potentially affecting financial records.

Affected Systems

Affected versions include Sylius 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5. Versions 2.0.18, 2.1.15, and 2.2.6 contain the patch that resolves the issue.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium severity, and the EPSS score is not available to gauge current exploitation likelihood. It is not listed in the CISA KEV catalog. The likely attack vector is through legitimate user interaction within the storefront after an order has been finalized; an authenticated customer can perform the exploit by accessing the cart page and invoking the stale LiveComponent actions. An attacker who has authenticated access can thereby alter or delete order data, potentially leading to financial loss or data integrity violations.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sylius to a patched release (2.0.18, 2.1.15, or 2.2.6 or later).
  • If an upgrade is not feasible, copy the patched FormComponent class into your application’s src/ directory and override the sylius_shop.twig.component.cart.form service definition to use that class.
  • Implement a server‑side check that prevents the cart page from presenting action options once an order is marked complete, thereby reducing the window of opportunity for exploitation.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5597-7rmh-97q5 Sylius: Cart FormComponent allows modification or deletion of an already-completed order
History

Fri, 11 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Sylius
Sylius sylius
Vendors & Products Sylius
Sylius sylius

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
Title Sylius: Cart FormComponent allows modification or deletion of an already-completed order
Weaknesses CWE-672
CWE-841
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:37:23.362Z

Reserved: 2026-06-09T20:16:59.647Z

Link: CVE-2026-53637

cve-icon Vulnrichment

Updated: 2026-09-09T15:37:18.461Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T23:17:24.697

Modified: 2026-09-09T21:04:42.813

Link: CVE-2026-53637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:00:15Z

Weaknesses
  • CWE-672

    Operation on a Resource after Expiration or Release

  • CWE-841

    Improper Enforcement of Behavioral Workflow