Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-48356 — Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-48356
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationSecurity VirtualizationWeb SecurityPenetration TestingLabs & Practice
GitHubabraxas/cve-2026-48356

CVE-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

12 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

Abraxas Labs — CVE-2026-48356

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-48356

CVE-2026-48356

Magento Open Source 2.4.8-p5 — Adobe

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user.

CVECVE-2026-48356 · CVE.org
CWECWE-434
CVSSCritical: 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
ProductMagento Open Source
Affectedall versions through 2.4.8-p5 (inclusive)
Patched2.4.8-2026-jul / APSB26-73 and later
Authunauthenticated (see source map)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only · vendor/client disclosure pack, not a scanner

Advisory (from the source map)

ImageContentValidator allows any filename without forbidden punctuation. ImageProcessor::getFileName keeps the caller extension. No option_id / option-type check on guest cart file_info. Hotfix APSB26-73 / 2.4.8-2026-jul.


Entry

  • Method: POST
  • Path: /rest/default/V1/guest-carts/{cartId}/items
  • Router: Unauthenticated REST guest cart. file_info polyglot bypasses ImageContentValidator; filename keeps .php. Written to pub/media/custom_options/quote/.
  • Notes: Unauthenticated CVE-2026-48356 CWE-434 Magento 2.4.8-p5 PolyShell. Witness: GHSA48356-WITNESS.php in add-to-cart JSON. Not eval. Not a reverse shell.

Call chain

  • POST /rest/default/V1/guest-carts returns cart id
  • POST /rest/default/V1/guest-carts/{id}/items with custom_options file_info GIF89a + <?= witness ?> named GHSA48356-WITNESS.php
  • Magento\Framework\Api\ImageContentValidator::isValid getimagesizefromstring only
  • Magento\Catalog\Model\Webapi\Product\Option\Type\File\Processor writes pub/media/custom_options/quote/.../GHSA48356-WITNESS.php

Lab preconditions

  • Magento Open Source / Adobe Commerce through 2.4.8-p5 / 2.4.9 without APSB26-73
  • REST guest-carts reachable
  • At least one salable simple product SKU (lab-sku)

Witness

guest-cart add-item HTTP JSON contains GHSA48356-WITNESS.php

Not success

  • eval/base64/system payload
  • reverse shell
  • patched APSB26-73

Patch / remediation

Do this first: Update Magento Open Source to 2.4.8-2026-jul / APSB26-73 or newer.

Verify after upgrade

  • Re-run CVE-2026-48356-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-48356-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
  • lab/run.sh
  • lab/seed-product.sh
  • lab/setup-magento.sh
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-48356 · NVD

  • CVE-2026-48356 · CVE.org

  • helpx.adobe.com/security/products/magento/apsb26-73.html

  • sansec.io/research/magento-polyshell

  • www.cve.org/CVERecord?id=CVE-2026-48356

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-48356 (PolyShell)

CWE: CWE-434
CVSS: Critical 9.3 (Adobe CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Sansec: unauthenticated REST upload.

## Description

Unauthenticated unrestricted file upload in Magento/Adobe Commerce guest-cart REST custom options. A GIF89a polyglot with a `.php` name bypasses `ImageContentValidator` and is written to `pub/media/custom_options/quote/`.

## Product

Magento Open Source 2.4.8-p5 (affected through 2.4.9 / 2.4.8-p5). Lab oracle is a witness filename in the REST body, not a shell.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool