StyleSmuggler gives unauthenticated attackers code execution on fully patched Magento and Adobe Commerce stores.
Public GraphQL input reaches PHP execution through failed-payment reminder rendering.
Magento Open Source and Adobe Commerce, internet-facing e-commerce applications normally hosted on Linux servers.
Unauthenticated server-side code execution and persistent backdoor installation
This leads because the path is unpatched, already present in observed compromises and reproduced on clean 2.4.7 through 2.4.9 installations.
Detail and 2 sources
An anonymous caller sends attacker-controlled styles through GraphQL, causes Magento to write poisoned PHP into a failure-report or template input, and triggers the ordinary failed-payment reminder path to execute it.
Observed attacks installed a background implant and cron persistence. No vendor patch was available in the reviewed material, so unexplained failed-payment rendering and the documented persistence locations warrant incident review.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required