πŸ” CVE Alert

CVE-2026-53637

MEDIUM 6.5

Sylius: Cart FormComponent allows modification or deletion of an already-completed order

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.

CWE CWE-672 CWE-841
Vendor sylius
Product sylius
Published Sep 8, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for sylius sylius

Be the first to know when new medium vulnerabilities affecting sylius sylius are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Sylius / Sylius
>= 2.0.0, < 2.0.18 >= 2.1.0, < 2.1.15 >= 2.2.0, < 2.2.6

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/Sylius/Sylius/security/advisories/GHSA-5597-7rmh-97q5