
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
9.1 CRITICAL
No preference is used, so your Magento is still upgradable.
The official fix still allows dangerous parameter to go to Setters, this patch does not allow it.
Magento/Adobe Commerce 2.3 or 2.4
composer require wubinworks/module-session-reaper-patch
If you like this extension or this extension helped you, please share and ★star☆ this repository, it's not hard!