HomeSecurityMagento: PolyShell vulnerability allows RCE and account theft

Magento: The PolyShell vulnerability allows RCE and account theft

Sansec warns of a critical security vulnerability in Magento's REST API that could allow unauthenticated attackers to upload arbitrary executable files and achieve code execution and account theft.

Magento PolyShell vulnerability

The vulnerability, codenamed PolyShell, relies on hiding malicious code in an image. There is no evidence that this vulnerability has been used in attacks. The file upload issue affects all versions of Magento Open Source and Adobe Commerce up to version 2.4.9-alpha2.

See also: Apple: Old iPhones vulnerable to Coruna and DarkSword exploits

The Dutch security firm explained that the issue arises because Magento's REST API accepts file uploads as part of custom options for cart items. When a product option has type 'file', Magento processes an embedded file_info object that contains base64-encoded file data, a MIME type, and a filename.

The file is then written to pub/media/custom_options/quote/ on the server.

Depending on the web server configuration, this vulnerability can allow:

  • remote code execution via PHP upload
  • account takeover via stored XSS

Sansec noted that Adobe has fixed the issue in the pre-release branch 2.4.9 as part of APSB25-94. However, current production versions remain unpatched. While Adobe provides a sample web server configuration that should largely mitigate the impact, most stores use a custom configuration from their hosting provider.

See also: Hackers exploit Langflow vulnerability

Magento: The PolyShell vulnerability allows RCE and account theft

To mitigate any potential risk, it is recommended that e‑commerce stores perform the following steps:

– Restrict access to the upload directory (“pub/media/custom_options/”).

– Verify that the nginx or Apache rules block access to the directory.

– Scan the stores for web shells, backdoors and other malicious software.

Sansec stressed that blocking access does not prevent uploads, so users will still be able to upload malicious code if a specialized Web Application Firewall (WAF) is not used.

See also: Ubiquiti UniFi: Vulnerability allows access to accounts

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Magento: The PolyShell vulnerability allows RCE and account theft

In summary, the PolyShell vulnerability highlights once again how critical security is in e-commerce platforms, especially when key functions such as APIs can be an entry point for attacks. While there is no evidence of active exploitation so far, the nature of the vulnerability – which combines malicious code obfuscation techniques and inadequate upload controls – makes it particularly dangerous for stores that do not take preventive measures.

It is therefore imperative that Magento administrators do not wait for the official release of a full patch, but proceed immediately to strengthen the security of their. Adopting correct settings on the web server, continuous monitoring for suspicious activity and the use of specialized tools such as a WAF can significantly reduce the risk. In an environment where threats are constantly evolving, prevention and vigilance remain the most powerful weapons.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS