Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-75650 — Disclosure pack and lab reproduction script for CVE-2026-75650, an unauthenticated SSTI RCE in Magento Open Source GraphQL email templates. | Kitploit
Tools/GitHubGitHub/abraxas/cve-2026-75650
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPayload DevelopmentLabs & Practice
GitHubabraxas/cve-2026-75650

CVE-2026-75650

Disclosure pack and lab reproduction script for CVE-2026-75650, an unauthenticated SSTI RCE in Magento Open Source GraphQL email templates.

2 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Abraxas Labs — CVE-2026-75650

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-75650

CVE-2026-75650

Magento Open Source 2.4.8-p5 — Adobe

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user.

CVECVE-2026-75650 · CVE.org
CWECWE-1336
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductMagento Open Source
Affectedall versions through 2.4.8-p5 (inclusive)
PatchedVULN-39341 / APSB26-146 and later
Authunauthenticated (see source map)
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only · vendor/client disclosure pack, not a scanner

Advisory (from the source map)

Magento email template filter signing str_replace; Email Preview styles; ArrayScanner::collectEntities include. Hotfix VULN-39341.


Entry

  • Method: POST
  • Path: /graphql
  • Router: Unauthenticated GraphQL. Store header logged unescaped. Guest cart billing SSTI smuggles Preview block. Payflow decline renders email and includes styles.first log path.
  • Notes: Unauthenticated CVE-2026-75650 CWE-1336 Magento 2.4.8-p5. Witness: GHSA75650-WITNESS in handlePayflowProResponse body. Not eval. Not a reverse shell.

Call chain

  • POST /graphql Store: <?= "GHSA75650-WITNESS" ?> logs into var/log/system.log
  • createEmptyCart + setGuestEmailOnCart + setBillingAddressOnCart with nested {{var}}/{{block Preview}}
  • POST /graphql?text=ColumnSet&styles={first:../var/log/system.log,...}&type=2 handlePayflowProResponse declined
  • Preview processes styles; ArrayScanner::collectEntities include()s the log

Lab preconditions

  • Magento Open Source / Adobe Commerce 2.4.4-2.4.9 without VULN-39341
  • GraphQL storefront reachable

Witness

handlePayflowProResponse HTTP body contains GHSA75650-WITNESS from included system.log.

Not success

  • eval/base64/system payload
  • reverse shell
  • patched VULN-39341

Patch / remediation

Do this first: Update Magento Open Source to VULN-39341 / APSB26-146 or newer.

Verify after upgrade

  • Re-run CVE-2026-75650-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-75650-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
  • lab/run.sh
  • lab/setup-magento.sh
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-75650 · NVD

  • CVE-2026-75650 · CVE.org

  • helpx.adobe.com/security/products/magento/apsb26-146.html

  • sansec.io/research/stylesmuggler-0day

  • www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650

  • www.cve.org/CVERecord?id=CVE-2026-75650

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-75650 (StyleSmuggler)

CWE: CWE-1336
CVSS: Critical 10.0 (Adobe). CISA KEV 2026-09-08.

## Description

Unauthenticated SSTI in Magento/Adobe Commerce email templates. A GraphQL `Store` header plants unescaped PHP in `system.log`. A guest cart billing address smuggles a signed `{{block}}`. `handlePayflowProResponse` on a declined Payflow payload renders the failed-payment email and `include`s the log via `styles.first`.

## Product

Magento Open Source 2.4.8-p5 (affected through 2.4.9). Lab oracle is a witness echo, not a shell.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Download Tool