Intel

AIKIDO-2025-10361

kyon147/laravel-shopify is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 10, 2025

73

High Risk

This Affects:

PHPkyon147/laravel-shopify
17.3.3 - 23.0.0
Fixed in 23.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to information disclosure due to improper access control in API routes protected by the VerifyShopify middleware. Any store can access data belonging to another store by appending a shop GET parameter with the target store's domain to an API request, bypassing authorization checks and exposing sensitive data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kyon147/laravel-shopify is vulnerable to Information Disclosure in versions 17.3.3 - 23.0.0.

How to fix this

Upgrade the kyon147/laravel-shopify library to the patch version.