Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
stylesmuggler-adobe-patches-mageos — composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-adobe-patches (Magento). | Kitploit
Tools/GitHubGitHub/disrex-group/stylesmuggler-adobe-patches-mageos
Vulnerability AnalysisConfiguration AuditingDevSecOpsSupply Chain SecurityArchived
GitHubdisrex-group/stylesmuggler-adobe-patches-mageos

stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-adobe-patches (Magento).

View Repository
1420 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

disrex/stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 fix (CVE-2026-75650, internal reference VULN-39341) for Mage-OS stores, applied through cweagans/composer-patches.

This is the Mage-OS companion to disrex/stylesmuggler-adobe-patches (that one is for Magento Open Source). Use this one only on Mage-OS.

Prefer a Mage-OS release with the fix. Mage-OS ships its own security releases. If one that contains the APSB26-146 fix is available for your line, update to it instead. This package is for a Mage-OS store that must patch in place until then.

Install

root@kitploit:~
composer require disrex/stylesmuggler-adobe-patches-mageos
composer -o install

There is one release per Mage-OS line, keyed on mage-os/product-community-edition. Composer picks the one matching your installed Mage-OS version.

Release (tag)Mage-OS versionMagento equivalent
2.4.6>=1.0.0 <1.0.32.4.6
2.4.7>=1.0.3 <1.1.02.4.7
2.4.8>=1.1.0 <3.0.02.4.8
2.4.9>=3.0.0 <4.0.02.4.9

Tested, and not tested

These are Adobe's Magento patches, applied to Mage-OS's packages. The files they touch are identical between Magento and Mage-OS at the levels we checked: the framework patch applies cleanly to mage-os/framework 2.3.0 (Magento 2.4.8-p5) and 3.4.0 (Magento 2.4.9), and neither carried the fix already.

Other Mage-OS versions and the non-framework packages are not individually tested. This is safe: patches apply through git apply, which is strict. It applies only where the surrounding lines match exactly, and refuses otherwise; it cannot land a security patch in the wrong place. Keep "composer-exit-on-patch-failure": true so a refusal stops your deploy with a clear message. If it refuses, update to a Mage-OS release with the fix.

Prerequisites

  • cweagans/composer-patches. Required. On v2 the patches apply automatically; on v1 also set "enable-patching": true under extra in your root composer.json.
  • Allow the plugin: "config": { "allow-plugins": { "cweagans/composer-patches": true } }.
  • Keep "composer-exit-on-patch-failure": true under extra.

It will not touch your Mage-OS

composer require never downgrades or reinstalls an installed, locked package on its own. The release for your line accepts the version you already run, so Composer keeps Mage-OS exactly where it is and only adds this metapackage and cweagans/composer-patches. A version with no matching release fails and reverts rather than changing anything.

What it applies

Adobe's fix for CVE-2026-75650 (CWE-1336, template-engine injection, CVSS 10.0), keyed on mage-os/framework, mage-os/module-backend, mage-os/module-email, mage-os/module-newsletter and mage-os/magento2-base. The patch files are Adobe's VULN-39341, repackaged by yellowteak, referenced by URL with sha256. The patch content is Adobe's, not covered by this package's MIT license.

After patching a store that was exposed

Patching shuts the door; it does not evict an attacker who already got in or invalidate secrets they read. Rotate the encryption key, database and admin credentials, API tokens and payment-gateway keys, and work through the cleanup guide in the mitigation repo.

Credits

The fix is Adobe's (APSB26-146). The composer-patches repackaging is yellowteak's. Discovery and the original advisory belong to Sansec.

Download Tool