Skip to finding
§
High
Edge — Commerce
Confirmed

StyleSmuggler gives unauthenticated attackers code execution on fully patched Magento and Adobe Commerce stores.

Public GraphQL input reaches PHP execution through failed-payment reminder rendering.

Affects

Magento Open Source and Adobe Commerce, internet-facing e-commerce applications normally hosted on Linux servers.

What it enables

Unauthenticated server-side code execution and persistent backdoor installation

Send attacker-controlled styles data through the public GraphQL surface.→↓Cause Magento to write poisoned PHP into a failure report or related template input.→↓Trigger the standard Payment Transaction Failed Reminder rendering path.→↓Magento executes the poisoned PHP in the storefront server context.→↓Observed attacks install a persistent background implant and cron entry.
Why this matters

This leads because the path is unpatched, already present in observed compromises and reproduced on clean 2.4.7 through 2.4.9 installations.

Detail and 2 sources
Required access

Internet reachability to a Magento or Adobe Commerce storefront with GraphQL enabled; no credentials or user interaction

Affected versions

Magento Open Source 2.4.6-p15 with July and August 2026 patches (confirmed victim), Magento Open Source 2.4.7 (researcher reproduced), Magento Open Source 2.4.8 (researcher reproduced), Magento Open Source 2.4.9 (researcher reproduced), Adobe Commerce current releases as of 2026-09-06, Magento Open Source 2.4.6-p15 observed compromised, Magento Open Source 2.4.7, 2.4.8 and 2.4.9 reproduced on clean installations, All current Magento Open Source and Adobe Commerce versions reported affected by Sansec, 2.4.6-p15 observed in an exploited store, 2.4.7 reproduced on a clean installation, 2.4.8 reproduced on a clean installation, 2.4.9 reproduced on a clean installation, Sansec reports all current Magento and Adobe Commerce versions affected as of 2026-09-05

Proof of concept

Demonstrated by the researcher

An anonymous caller sends attacker-controlled styles through GraphQL, causes Magento to write poisoned PHP into a failure-report or template input, and triggers the ordinary failed-payment reminder path to execute it.

Observed attacks installed a background implant and cron persistence. No vendor patch was available in the reviewed material, so unexplained failed-payment rendering and the documented persistence locations warrant incident review.

Evidence
Sansec observed compromises beginning September 4 and reproduced the complete unauthenticated chain on clean 2.4.7, 2.4.8 and 2.4.9 installations.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026