logo

PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks

ID: d371d2ab-a1b0-5d22-95aa-9209ebb6d9ea

STIX ID: report--d371d2ab-a1b0-5d22-95aa-9209ebb6d9ea

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-03-21

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Sansec disclosed a critical REST API vulnerability dubbed “PolyShell” in Magento and Adobe Commerce that allows unauthenticated base64 file uploads to pub/media/custom_options/quote/, enabling potential remote code execution or stored XSS in affected versions (up to 2.4.9-alpha2). The issue has existed since Magento 2’s first release, was only fixed in a 2.4.9 pre-release with no standalone patch for production, and exploit code is circulating; Sansec recommends WAFs, restricting upload directories, and system scanning to mitigate risk while noting many stores use configurations that leave them exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.