
Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-48356
Magento Open Source 2.4.8-p5 — Adobe
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user.
| CVE | CVE-2026-48356 · CVE.org |
| CWE | CWE-434 |
| CVSS | Critical: 9.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
| Product | Magento Open Source |
| Affected | all versions through 2.4.8-p5 (inclusive) |
| Patched | 2.4.8-2026-jul / APSB26-73 and later |
| Auth | unauthenticated (see source map) |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only · vendor/client disclosure pack, not a scanner |
ImageContentValidator allows any filename without forbidden punctuation. ImageProcessor::getFileName keeps the caller extension. No option_id / option-type check on guest cart file_info. Hotfix APSB26-73 / 2.4.8-2026-jul.
POST/rest/default/V1/guest-carts/{cartId}/itemsPOST /rest/default/V1/guest-carts returns cart idPOST /rest/default/V1/guest-carts/{id}/items with custom_options file_info GIF89a + <?= witness ?> named GHSA48356-WITNESS.phpMagento\Framework\Api\ImageContentValidator::isValid getimagesizefromstring onlyMagento\Catalog\Model\Webapi\Product\Option\Type\File\Processor writes pub/media/custom_options/quote/.../GHSA48356-WITNESS.phpguest-cart add-item HTTP JSON contains GHSA48356-WITNESS.php
Do this first: Update Magento Open Source to 2.4.8-2026-jul / APSB26-73 or newer.
Verify after upgrade
CVE-2026-48356-Abraxas-Labs.py against the patched build: the mapped witness must not appear.If you cannot update immediately
Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.
python3 CVE-2026-48356-Abraxas-Labs.py
Success is the witness above in the response body. Generic 200 HTML is not it.
Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.
cd lab
docker compose up --force-recreate
Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.
# CVE-2026-48356 (PolyShell)
CWE: CWE-434
CVSS: Critical 9.3 (Adobe CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Sansec: unauthenticated REST upload.
## Description
Unauthenticated unrestricted file upload in Magento/Adobe Commerce guest-cart REST custom options. A GIF89a polyglot with a `.php` name bypasses `ImageContentValidator` and is written to `pub/media/custom_options/quote/`.
## Product
Magento Open Source 2.4.8-p5 (affected through 2.4.9 / 2.4.8-p5). Lab oracle is a witness filename in the REST body, not a shell.
This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.
This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.