Description
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Published: 2026-09-08
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to order data and potential phishing redirect
Action: Immediate Patch
AI Analysis

Impact

Idempotent IDOR flaw allows an attacker who knows a payment request hash to retrieve sensitive order information from Sylius APIs. The GET and PUT payment request endpoints resolve the request solely by the hash, without verifying the requester’s ownership of the linked order. Once the hash is discovered, an attacker can read the payment request and use the exposed payment IRI to retrieve the order’s tokenValue, which grants full access to the order, customer details, and totals. Furthermore, the attacker can modify the payment request payload, changing redirect URLs such as target_path and after_path, enabling phishing or man‑in‑the‑middle attacks. The vulnerability is rooted in improper authorization and is catalogued as CWE‑639.

Affected Systems

Sylius eCommerce Framework is affected. Versions starting with 2.0.0 up to but not including 2.0.18, 2.1.15, and 2.2.6 contain the flaw. Upgrades to 2.0.18 or newer, 2.1.15 or newer, or 2.2.6 or newer resolve the issue.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The exploit requires a valid payment request hash, which is a UUID and must be obtained out‑of‑band (e.g., from logs, shared links, referrer headers, or a co‑located client). Authentication or knowledge of the order token is not required once the hash is known. EPSS is not available, and the vulnerability is currently not listed in CISA KEV. The attack vector is remote and relies on REST API exposure; although obtaining the hash is nontrivial, the low barrier to compromise the order once the hash is known makes the risk moderate.

Generated by OpenCVE AI on September 9, 2026 at 08:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Sylius to version 2.0.18, 2.1.15, 2.2.6, or later to apply the vendor‐issued fix.
  • If a patch cannot be applied immediately, add a query‑extension filter to the GET payment‑request operation to restrict results to the authenticated customer’s orders.
  • Decorate the PUT state provider to enforce ownership verification before updating payment request payloads.
  • Guard the POST /api/v2/shop/orders/{tokenValue}/payment‑requests endpoint with a command‑bus middleware to ensure the caller owns the target order.

Generated by OpenCVE AI on September 9, 2026 at 08:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mr9r-h354-966r Sylius: IDOR on Shop Payment Request API endpoints
History

Fri, 11 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Sylius
Sylius sylius
Vendors & Products Sylius
Sylius sylius

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Title Sylius: IDOR on Shop Payment Request API endpoints
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T16:03:44.749Z

Reserved: 2026-06-09T20:16:59.648Z

Link: CVE-2026-53639

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:54.108Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T23:17:24.987

Modified: 2026-09-09T21:04:42.813

Link: CVE-2026-53639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:15:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key