Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
cve-2026-75650-magento-validation-lab — Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341. | Kitploit
ツール/GitHubGitHub/dinosn/cve-2026-75650-magento-validation-lab
Vulnerability AnalysisExploitationWeb SecurityLearning & EducationCurated ResourcesLabs & Practice
GitHubdinosn/cve-2026-75650-magento-validation-lab

cve-2026-75650-magento-validation-lab

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

リポジトリを見る
612315日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2026-75650 / VULN-39341 Docker validation lab

This standalone lab reproduces the complete unauthenticated StyleSmuggler HTTP chain on a revision-pinned Magento Open Source 2.4.9 checkout. It then applies Adobe's VULN-39341 patch and proves that the identical request sequence no longer reaches PHP execution.

The proof is deliberately marker-only. The poisoned report evaluates one fixed hash('sha256', fresh_nonce) expression. The expected digest is never sent to Magento, so seeing it in the Stage 2 response independently proves that PHP parsed and executed the report. The PoC has no command runner, downloader, callback, proxy, or operator-supplied PHP.

Scope and claim

The lab provides:

  • a stock Magento 2.4.9 Docker stack pinned to Git revision 755e34dd689021c5165db9d35ecff74f7dc51527;
  • a complete stock HTTP path with no synthetic Magento controller or module;
  • a vulnerable/patched A/B for report storage, direct component execution, and the complete unauthenticated chain;
  • the checksum-pinned 2.4.9 VULN-39341 monorepo patch;
  • a read-only Docker validator for an owner-controlled Magento filesystem.

This is a lab-assisted proof for the pinned build. It is not a scanner result or an assumption based on a report ID, HTTP status, failed email, or file upload. The fresh response marker is the execution oracle.

Safety and requirements

Use only this disposable lab. The HTTP PoC refuses every non-loopback target and accepts no arbitrary payload or report path. Do not place the probes under a production web root. For an existing installation, use the read-only validator or a disposable staging clone.

Requirements:

  • Docker with Compose v2;
  • Python 3.10 or newer on the host;
  • approximately 6 GB free RAM and 5 GB free disk;
  • outbound access during the first build and Magento installation.

Only nginx is published, and only on 127.0.0.1:8096 by default. MariaDB, Redis, OpenSearch, PHP-FPM, and the secondary report gateway are not exposed to the host network. The public gateway selects production-style Magento error handling so Stage 1 creates a normal var/report record.

Quick start

root@kitploit:~
cd docker-lab
cp .env.example .env
docker compose up -d --build
docker compose logs -f php

The initial Magento clone, dependency install, and application install normally take 15–40 minutes. When the PHP log prints Ready, run:

root@kitploit:~
make ab

The A/B command always attempts to leave the source patched and removes the exact report artifacts disclosed during its HTTP runs.

Required result

The test passes only when all three proof layers match their controls:

root@kitploit:~
Unpatched report:    raw-tag=true,  guard=false
Patched report:      raw-tag=false, guard=true, neutralized=true
Unpatched component: marker=true
Patched component:   marker=false

Full HTTP, vulnerable: execution_observed=true,  expectation_met=true
Full HTTP, patched:    execution_observed=false, expectation_met=true

[PASS] Report storage, component execution, and full HTTP execution match all A/B controls.

Complete HTTP flow

poc/http_rce_probe.py sends only unauthenticated requests to the loopback Magento gateway:

root@kitploit:~
poison a normal Magento failure report
  -> createEmptyCart
  -> setGuestEmailOnCart
  -> setBillingAddressOnCart with the recursive formatter construction
  -> handlePayflowProResponse with a declined response
  -> billing-address formatter signs an unresolved Preview block
  -> failed-payment email filter constructs Email Template Preview
  -> Preview reads request query parameters type/text/styles
  -> ColumnSet -> UrlGeneratorFactory -> Aws S3Client
  -> with_resolved callback -> ArrayScanner::collectEntities()
  -> include the poisoned report
  -> fresh SHA-256 response marker

The important connector is the billing address. A self-referencing postcode, the stock HTML address format, and nested template directives cause Magento's basic formatter to wrap the unresolved Preview block in Magento's own deferred directive signature. The later failed-payment email filter shares that signature provider and accepts the block. Preview is then constructed directly by Layout inside the GraphQL request; no admin route is dispatched.

Individual controls

root@kitploit:~
make http-vulnerable  # requires execution_observed=true
make http-patched     # requires execution_observed=false
make component-ab     # decomposed report/component controls only

The HTTP wrappers select the requested source state, run the loopback-only probe, and remove the exact report ID returned by Magento. To inspect the raw probe directly in the disposable lab:

root@kitploit:~
make vulnerable
python3 poc/http_rce_probe.py \
  --target http://127.0.0.1:8096 \
  --expect vulnerable

make patched
python3 poc/http_rce_probe.py \
  --target http://127.0.0.1:8096 \
  --expect patched

Direct invocation leaves the generated report for inspection; the make http-* wrappers perform cleanup.

What “marker-only full HTTP RCE probe” means

  • Marker-only: PHP computes a fresh digest. It does not start a process, write a web shell, download anything, or contact another host.
  • Full HTTP: every vulnerable application transition begins with stock unauthenticated HTTP requests. No helper is copied into Magento and no custom route connects the source and sink.
  • RCE probe: the digest can only appear after the poisoned report has been parsed as PHP. Because the report content itself is request-controlled, that demonstrates the code-execution consequence without shipping a general payload facility.

The direct component probe remains available because it localizes failures in the downstream gadget independently from the recursive address-formatting connector.

Validate an owner-controlled Magento tree

This check never starts Magento or executes code from the mounted tree. The container has no network, no Linux capabilities, a read-only root filesystem, and a read-only target mount.

root@kitploit:~
make validate TARGET=/absolute/path/to/magento

Expected fully patched verdict:

root@kitploit:~
Summary: 9/9 controls present
Verdict: FULL_CONTROL_SET_PRESENT

Anything less is reported as FULL_CONTROL_SET_NOT_CONFIRMED, not automatically as exploitable. Confirm the exact Commerce edition/version and apply Adobe's version-matched patch through its supported deployment process.

Production remediation

Use the official bulletin and the patch matching the deployed release:

  • https://helpx.adobe.com/security/products/magento/apsb26-146.html
  • https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146
  • https://repo.magento.com/patch/VULN-39341-composer-patches.zip

The patch embedded here is path-mapped only for the public 2.4.9 monorepo lab. Do not apply it directly to a production Composer installation. Patching also does not remove an existing implant or restore exposed credentials.

Research provenance

The missing HTTP connector was published and independently demonstrated by Fortbridge on 12 September 2026:

  • https://fortbridge.co.uk/research/stylesmuggler-magento-unauthenticated-rce/
  • https://github.com/fortbridge/stylesmuggler

This lab uses an independently implemented, loopback-only marker probe and retains its own pinned Magento and Adobe-patch A/B controls.

See Technical notes for the data flow, patch controls, and retrospective. Exact local test results are recorded in VALIDATION.md.

Cleanup

root@kitploit:~
make down   # preserve volumes
make reset  # delete this lab's source, database, and OpenSearch volumes

License

Lab-authored material is MIT licensed. See LICENSE and NOTICE.md.

ツールをダウンロード