Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-75650 — CVE-2026-75650 के लिए डिस्क्लोज़र पैक और लैब रिप्रोडक्शन स्क्रिप्ट, जो Magento Open Source GraphQL ईमेल टेम्पलेट्स में एक अनऑथेंटिकेटेड SSTI RCE है। | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-75650
भेद्यता स्कैनरभेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणवेब सुरक्षापेनिट्रेशन टेस्टिंगपेलोड डेवलपमेंटलैब और अभ्यास
GitHubabraxas/cve-2026-75650

CVE-2026-75650

CVE-2026-75650 के लिए डिस्क्लोज़र पैक और लैब रिप्रोडक्शन स्क्रिप्ट, जो Magento Open Source GraphQL ईमेल टेम्पलेट्स में एक अनऑथेंटिकेटेड SSTI RCE है।

2 दिन पहलेअभी तक समीक्षित नहीं
रिपॉजिटरी देखें

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Abraxas Labs — CVE-2026-75650

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  CVE-2026-75650

CVE-2026-75650

Magento Open Source 2.4.8-p5 — Adobe

Adobe Commerce एक Improper Neutralization of Special Elements Used in a Template Engine vulnerability से प्रभावित है, जिसके परिणामस्वरूप वर्तमान उपयोगकर्ता के संदर्भ में मनमाना कोड निष्पादन हो सकता है।

CVECVE-2026-75650 · CVE.org
CWECWE-1336
CVSSCritical: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductMagento Open Source
Affected2.4.8-p5 तक के सभी संस्करण (सम्मिलित)
PatchedVULN-39341 / APSB26-146 और बाद के संस्करण
Authunauthenticated (स्रोत मैप देखें)
LicenseGNU Affero GPL v3.0
Labकेवल 127.0.0.1 · vendor/client disclosure pack, स्कैनर नहीं

Advisory (स्रोत मैप से)

Magento email template filter signing str_replace; Email Preview styles; ArrayScanner::collectEntities include. Hotfix VULN-39341.


Entry

  • Method: POST
  • Path: /graphql
  • Router: Unauthenticated GraphQL. Store header logged unescaped. Guest cart billing SSTI smuggles Preview block. Payflow decline renders email and includes styles.first log path.
  • Notes: Unauthenticated CVE-2026-75650 CWE-1336 Magento 2.4.8-p5. Witness: GHSA75650-WITNESS in handlePayflowProResponse body. Not eval. Not a reverse shell.

Call chain

  • POST /graphql Store: <?= "GHSA75650-WITNESS" ?> logs into var/log/system.log
  • createEmptyCart + setGuestEmailOnCart + setBillingAddressOnCart with nested {{var}}/{{block Preview}}
  • POST /graphql?text=ColumnSet&styles={first:../var/log/system.log,...}&type=2 handlePayflowProResponse declined
  • Preview processes styles; ArrayScanner::collectEntities include()s the log

Lab preconditions

  • Magento Open Source / Adobe Commerce 2.4.4-2.4.9 without VULN-39341
  • GraphQL storefront reachable

Witness

handlePayflowProResponse HTTP body contains GHSA75650-WITNESS from included system.log.

Not success

  • eval/base64/system payload
  • reverse shell
  • patched VULN-39341

Patch / remediation

Do this first: Update Magento Open Source to VULN-39341 / APSB26-146 or newer.

Verify after upgrade

  • Re-run CVE-2026-75650-Abraxas-Labs.py against the patched build: the mapped witness must not appear.
  • Confirm the vendor advisory / changeset in the deployed tree (see references).
  • A WAF signature is delay, not a patch.

If you cannot update immediately

  • Disable or isolate the affected component.
  • Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Reproduction (authorized lab)

Target only http://127.0.0.1:8088 (or the loopback you bound). Do not point this script at the internet.

root@kitploit:~
python3 CVE-2026-75650-Abraxas-Labs.py

Success is the witness above in the response body. Generic 200 HTML is not it.


Lab images

Loopback stack used to reproduce. Official images unless a Dockerfile in this folder builds from source.

  • lab/docker-compose.yml
  • lab/Dockerfile
  • lab/run.sh
  • lab/setup-magento.sh
root@kitploit:~
cd lab
docker compose up --force-recreate

Bind the vulnerable product tree next to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except 127.0.0.1.


References

  • CVE-2026-75650 · NVD

  • CVE-2026-75650 · CVE.org

  • helpx.adobe.com/security/products/magento/apsb26-146.html

  • sansec.io/research/stylesmuggler-0day

  • www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650

  • www.cve.org/CVERecord?id=CVE-2026-75650

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


Records (structured)

root@kitploit:~
# CVE-2026-75650 (StyleSmuggler)

CWE: CWE-1336
CVSS: Critical 10.0 (Adobe). CISA KEV 2026-09-08.

## Description

Unauthenticated SSTI in Magento/Adobe Commerce email templates. A GraphQL `Store` header plants unescaped PHP in `system.log`. A guest cart billing address smuggles a signed `{{block}}`. `handlePayflowProResponse` on a declined Payflow payload renders the failed-payment email and `include`s the log via `styles.first`.

## Product

Magento Open Source 2.4.8-p5 (affected through 2.4.9). Lab oracle is a witness echo, not a shell.

License

This disclosure pack is licensed under the GNU Affero General Public License v3.0. See LICENSE.


Disclaimer

This pack is for the vendor, the site owner, and licensed labs. The script talks to 127.0.0.1. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें