important · Edge — Commerce
StyleSmuggler requests are giving unauthenticated callers code execution on Adobe Commerce and Magento stores.
Affects
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, PHP e-commerce storefronts commonly hosted on Linux servers.
An anonymous /graphql request injects styles data that poisons template output, and a failed-payment email path executes the injected PHP.
Detail and 3 sources
Sansec reproduced the complete chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations.
Adobe shipped a hotfix.