Skip to finding
important · Edge — Commerce

StyleSmuggler requests are giving unauthenticated callers code execution on Adobe Commerce and Magento stores.

Affects

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, PHP e-commerce storefronts commonly hosted on Linux servers.

An anonymous /graphql request injects styles data that poisons template output, and a failed-payment email path executes the injected PHP.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026