๐Ÿ” CVE Alert

CVE-2026-31821

UNKNOWN 0.0

Sylius is Missing Authorization in API v2 Add Item Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers' carts by knowing the cart tokenValue. An attacker who obtains a cart tokenValue can add arbitrary items to another customer's cart. The endpoint returns the full cart representation in the response (HTTP 201). The issue is fixed in versions: 2.0.16, 2.1.12, 2.2.3 and above.

CWE CWE-862
Vendor sylius
Product sylius
Published Mar 10, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for sylius sylius

Be the first to know when new unknown vulnerabilities affecting sylius sylius are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sylius / Sylius
>= 2.2.0, < 2.2.3 >= 2.1.0, < 2.1.12 >= 2.0.0, < 2.0.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Sylius/Sylius/security/advisories/GHSA-wjmg-4cq5-m8hg