Adobe Commerce and Magento Improper Input Validation Vulnerability
cve CVE-2025-54236 2 sources, 2 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Adobe Commerce and Magento Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236 the claim
Adobe Commerce and Magento Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cwes cwes | CISA Known Exploited Vulnerabilities | CWE-20receipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2025-11-14receipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Unknownreceipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Platform platform | Metasploit exploit modules | Linux,PHP,Unix,Windowsreceipt
What the source handed over{
"aliases": [],
"arch": "php, cmd",
"author": [
"Blaklis",
"Tomais Williamson",
"Valentin Lobstein <chocapikk@leakix.net>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits CVE-2025-54236 (SessionReaper), a critical vulnerability in\n Magento/Adobe Commerce that allows unauthenticated remote code execution.\n\n The vulnerability stems from improper handling of nested deserialization in the\n payment method context, combined with an unauthenticated file upload endpoint.\n\n The exploit chain consists of three steps:\n 1. Upload a malicious PHP session file containing a Guzzle/FW1 deserialization\n payload via the unauthenticated /customer/address_file/upload endpoint\n 2. Trigger deserialization by sending a crafted JSON payload to the REST API\n endpoint /rest/default/V1/guest-carts/{cart_id}/order that modifies the\n session savePath to point to the uploaded file\n 3. Execute the uploaded PHP code to gain remote code execution\n\n This vulnerability affects Magento 2.x instances configured to use file-based\n session storage. Patched versions will return a 400 Bad Request response instead\n of processing the malicious payload.",
"disclosure_date": "2025-10-22",
"fullname": "exploit/multi/http/magento_sessionreaper",
"is_install_path": true,
"mod_time": "2025-12-17 16:12:31 +0000",
"name": "Magento SessionReaper",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs",
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/magento_sessionreaper.rb",
"platform": "Linux,PHP,Unix,Windows",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/magento_sessionreaper",
"references": [
"CVE-2025-54236",
"URL-https://slcyber.io/research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/",
"URL-https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397"
],
"rport": 80,
"session_types": false,
"targets": [
"PHP In-Memory",
"Unix/Linux Command Shell",
"Windows Command Shell"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Commerce and Magentoreceipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "php, cmd",
"author": [
"Blaklis",
"Tomais Williamson",
"Valentin Lobstein <chocapikk@leakix.net>"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits CVE-2025-54236 (SessionReaper), a critical vulnerability in\n Magento/Adobe Commerce that allows unauthenticated remote code execution.\n\n The vulnerability stems from improper handling of nested deserialization in the\n payment method context, combined with an unauthenticated file upload endpoint.\n\n The exploit chain consists of three steps:\n 1. Upload a malicious PHP session file containing a Guzzle/FW1 deserialization\n payload via the unauthenticated /customer/address_file/upload endpoint\n 2. Trigger deserialization by sending a crafted JSON payload to the REST API\n endpoint /rest/default/V1/guest-carts/{cart_id}/order that modifies the\n session savePath to point to the uploaded file\n 3. Execute the uploaded PHP code to gain remote code execution\n\n This vulnerability affects Magento 2.x instances configured to use file-based\n session storage. Patched versions will return a 400 Bad Request response instead\n of processing the malicious payload.",
"disclosure_date": "2025-10-22",
"fullname": "exploit/multi/http/magento_sessionreaper",
"is_install_path": true,
"mod_time": "2025-12-17 16:12:31 +0000",
"name": "Magento SessionReaper",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"ioc-in-logs",
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/magento_sessionreaper.rb",
"platform": "Linux,PHP,Unix,Windows",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/magento_sessionreaper",
"references": [
"CVE-2025-54236",
"URL-https://slcyber.io/research-center/why-nested-deserialization-is-still-harmful-magento-rce-cve-2025-54236/",
"URL-https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397"
],
"rport": 80,
"session_types": false,
"targets": [
"PHP In-Memory",
"Unix/Linux Command Shell",
"Windows Command Shell"
],
"type": "exploit"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Adobereceipt
What the source handed over{
"cveID": "CVE-2025-54236",
"cwes": "CWE-20",
"dateAdded": "2025-10-24",
"dueDate": "2025-11-14",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Unknown",
"notes": "https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54236",
"product": "Commerce and Magento",
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
"shortDescription": "Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.",
"vendorProject": "Adobe",
"vulnerabilityName": "Adobe Commerce and Magento Improper Input Validation Vulnerability"
} | — |
vulnerability
| Adobe Commerce and Magento Improper Input Validation Vulnerability zetlyn/cve-kev · 2025-10-24 | cwes CWE-20 due_date 2025-11-14 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Commerce and Magento vendor_project Adobe |
exploit
| Magento SessionReaper zetlyn/cve-metasploit · 2025-10-22 | platform Linux,PHP,Unix,Windows rank 600 | source |