Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
cve-2026-75650-magento-validation-lab — Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341. | Kitploit
工具/GitHubGitHub/dinosn/cve-2026-75650-magento-validation-lab
Vulnerability AnalysisExploitationWeb SecurityLearning & EducationCurated ResourcesLabs & Practice
GitHubdinosn/cve-2026-75650-magento-validation-lab

cve-2026-75650-magento-validation-lab

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
612316天前尚未审核
分享
内容在请求的语言中不可用。显示英文版本。

CVE-2026-75650 / VULN-39341 Docker validation lab

This standalone lab reproduces the complete unauthenticated StyleSmuggler HTTP chain on a revision-pinned Magento Open Source 2.4.9 checkout. It then applies Adobe's VULN-39341 patch and proves that the identical request sequence no longer reaches PHP execution.

The proof is deliberately marker-only. The poisoned report evaluates one fixed hash('sha256', fresh_nonce) expression. The expected digest is never sent to Magento, so seeing it in the Stage 2 response independently proves that PHP parsed and executed the report. The PoC has no command runner, downloader, callback, proxy, or operator-supplied PHP.

Scope and claim

The lab provides:

  • a stock Magento 2.4.9 Docker stack pinned to Git revision 755e34dd689021c5165db9d35ecff74f7dc51527;
  • a complete stock HTTP path with no synthetic Magento controller or module;
  • a vulnerable/patched A/B for report storage, direct component execution, and the complete unauthenticated chain;
  • the checksum-pinned 2.4.9 VULN-39341 monorepo patch;
  • a read-only Docker validator for an owner-controlled Magento filesystem.

This is a lab-assisted proof for the pinned build. It is not a scanner result or an assumption based on a report ID, HTTP status, failed email, or file upload. The fresh response marker is the execution oracle.

Safety and requirements

Use only this disposable lab. The HTTP PoC refuses every non-loopback target and accepts no arbitrary payload or report path. Do not place the probes under a production web root. For an existing installation, use the read-only validator or a disposable staging clone.

Requirements:

  • Docker with Compose v2;
  • Python 3.10 or newer on the host;
  • approximately 6 GB free RAM and 5 GB free disk;
  • outbound access during the first build and Magento installation.

Only nginx is published, and only on 127.0.0.1:8096 by default. MariaDB, Redis, OpenSearch, PHP-FPM, and the secondary report gateway are not exposed to the host network. The public gateway selects production-style Magento error handling so Stage 1 creates a normal var/report record.

Quick start

root@kitploit:~
cd docker-lab
cp .env.example .env
docker compose up -d --build
docker compose logs -f php

The initial Magento clone, dependency install, and application install normally take 15–40 minutes. When the PHP log prints Ready, run:

root@kitploit:~
make ab

The A/B command always attempts to leave the source patched and removes the exact report artifacts disclosed during its HTTP runs.

Required result

The test passes only when all three proof layers match their controls:

root@kitploit:~
Unpatched report:    raw-tag=true,  guard=false
Patched report:      raw-tag=false, guard=true, neutralized=true
Unpatched component: marker=true
Patched component:   marker=false

Full HTTP, vulnerable: execution_observed=true,  expectation_met=true
Full HTTP, patched:    execution_observed=false, expectation_met=true

[PASS] Report storage, component execution, and full HTTP execution match all A/B controls.

Complete HTTP flow

poc/http_rce_probe.py sends only unauthenticated requests to the loopback Magento gateway:

root@kitploit:~
poison a normal Magento failure report
  -> createEmptyCart
  -> setGuestEmailOnCart
  -> setBillingAddressOnCart with the recursive formatter construction
  -> handlePayflowProResponse with a declined response
  -> billing-address formatter signs an unresolved Preview block
  -> failed-payment email filter constructs Email Template Preview
  -> Preview reads request query parameters type/text/styles
  -> ColumnSet -> UrlGeneratorFactory -> Aws S3Client
  -> with_resolved callback -> ArrayScanner::collectEntities()
  -> include the poisoned report
  -> fresh SHA-256 response marker

The important connector is the billing address. A self-referencing postcode, the stock HTML address format, and nested template directives cause Magento's basic formatter to wrap the unresolved Preview block in Magento's own deferred directive signature. The later failed-payment email filter shares that signature provider and accepts the block. Preview is then constructed directly by Layout inside the GraphQL request; no admin route is dispatched.

Individual controls

root@kitploit:~
make http-vulnerable  # requires execution_observed=true
make http-patched     # requires execution_observed=false
make component-ab     # decomposed report/component controls only

The HTTP wrappers select the requested source state, run the loopback-only probe, and remove the exact report ID returned by Magento. To inspect the raw probe directly in the disposable lab:

root@kitploit:~
make vulnerable
python3 poc/http_rce_probe.py \
  --target http://127.0.0.1:8096 \
  --expect vulnerable

make patched
python3 poc/http_rce_probe.py \
  --target http://127.0.0.1:8096 \
  --expect patched

Direct invocation leaves the generated report for inspection; the make http-* wrappers perform cleanup.

What “marker-only full HTTP RCE probe” means

  • Marker-only: PHP computes a fresh digest. It does not start a process, write a web shell, download anything, or contact another host.
  • Full HTTP: every vulnerable application transition begins with stock unauthenticated HTTP requests. No helper is copied into Magento and no custom route connects the source and sink.
  • RCE probe: the digest can only appear after the poisoned report has been parsed as PHP. Because the report content itself is request-controlled, that demonstrates the code-execution consequence without shipping a general payload facility.

The direct component probe remains available because it localizes failures in the downstream gadget independently from the recursive address-formatting connector.

Validate an owner-controlled Magento tree

This check never starts Magento or executes code from the mounted tree. The container has no network, no Linux capabilities, a read-only root filesystem, and a read-only target mount.

root@kitploit:~
make validate TARGET=/absolute/path/to/magento

Expected fully patched verdict:

root@kitploit:~
Summary: 9/9 controls present
Verdict: FULL_CONTROL_SET_PRESENT

Anything less is reported as FULL_CONTROL_SET_NOT_CONFIRMED, not automatically as exploitable. Confirm the exact Commerce edition/version and apply Adobe's version-matched patch through its supported deployment process.

Production remediation

Use the official bulletin and the patch matching the deployed release:

  • https://helpx.adobe.com/security/products/magento/apsb26-146.html
  • https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146
  • https://repo.magento.com/patch/VULN-39341-composer-patches.zip

The patch embedded here is path-mapped only for the public 2.4.9 monorepo lab. Do not apply it directly to a production Composer installation. Patching also does not remove an existing implant or restore exposed credentials.

Research provenance

The missing HTTP connector was published and independently demonstrated by Fortbridge on 12 September 2026:

  • https://fortbridge.co.uk/research/stylesmuggler-magento-unauthenticated-rce/
  • https://github.com/fortbridge/stylesmuggler

This lab uses an independently implemented, loopback-only marker probe and retains its own pinned Magento and Adobe-patch A/B controls.

See Technical notes for the data flow, patch controls, and retrospective. Exact local test results are recorded in VALIDATION.md.

Cleanup

root@kitploit:~
make down   # preserve volumes
make reset  # delete this lab's source, database, and OpenSearch volumes

License

Lab-authored material is MIT licensed. See LICENSE and NOTICE.md.

下载工具