
CVE-2026-75650 के लिए डिस्क्लोज़र पैक और लैब रिप्रोडक्शन स्क्रिप्ट, जो Magento Open Source GraphQL ईमेल टेम्पलेट्स में एक अनऑथेंटिकेटेड SSTI RCE है।
abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-75650
Magento Open Source 2.4.8-p5 — Adobe
Adobe Commerce एक Improper Neutralization of Special Elements Used in a Template Engine vulnerability से प्रभावित है, जिसके परिणामस्वरूप वर्तमान उपयोगकर्ता के संदर्भ में मनमाना कोड निष्पादन हो सकता है।
| CVE | CVE-2026-75650 · CVE.org |
| CWE | CWE-1336 |
| CVSS | Critical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Product | Magento Open Source |
| Affected | 2.4.8-p5 तक के सभी संस्करण (सम्मिलित) |
| Patched | VULN-39341 / APSB26-146 और बाद के संस्करण |
| Auth | unauthenticated (स्रोत मैप देखें) |
| License | GNU Affero GPL v3.0 |
| Lab | केवल 127.0.0.1 · vendor/client disclosure pack, स्कैनर नहीं |
Magento email template filter signing str_replace; Email Preview styles; ArrayScanner::collectEntities include. Hotfix VULN-39341.
POST/graphqlPOST /graphql Store: <?= "GHSA75650-WITNESS" ?> logs into var/log/system.logcreateEmptyCart + setGuestEmailOnCart + setBillingAddressOnCart with nested {{var}}/{{block Preview}}POST /graphql?text=ColumnSet&styles={first:../var/log/system.log,...}&type=2 handlePayflowProResponse declinedPreview processes styles; ArrayScanner::collectEntities include()s the loghandlePayflowProResponse HTTP body contains GHSA75650-WITNESS from included system.log.
Do this first: Update Magento Open Source to VULN-39341 / APSB26-146 or newer.
Verify after upgrade
CVE-2026-75650-Abraxas-Labs.py against the patched build: the mapped witness must not appear.If you cannot update immediately
Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.
python3 CVE-2026-75650-Abraxas-Labs.py
Success is the witness above in the response body. Generic 200 HTML is not it.
Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.
cd lab
docker compose up --force-recreate
Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.
# CVE-2026-75650 (StyleSmuggler)
CWE: CWE-1336
CVSS: Critical 10.0 (Adobe). CISA KEV 2026-09-08.
## Description
Unauthenticated SSTI in Magento/Adobe Commerce email templates. A GraphQL `Store` header plants unescaped PHP in `system.log`. A guest cart billing address smuggles a signed `{{block}}`. `handlePayflowProResponse` on a declined Payflow payload renders the failed-payment email and `include`s the log via `styles.first`.
## Product
Magento Open Source 2.4.8-p5 (affected through 2.4.9). Lab oracle is a witness echo, not a shell.
This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.
This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.