
CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views
| Field | Details |
|---|---|
| CVE ID | CVE-2026-23498 |
| Severity | HIGH |
| Advisory | View Advisory |
| Discovered by | Lukasz Rybak |
We fixed with CVE-2023-2017 Twig filters to only be executed with allowed functions. However there was a regression that lead to an array and array crafted PHP Closure not checked being against allow list for the map(...) override
Patched in 6.7.6.1
Install the security plugin
(https://github.com/advisories/GHSA-7v2v-9rm4-7m8f)
This CVE was responsibly disclosed following coordinated vulnerability disclosure practices. The information provided here is for educational and defensive purposes only.