Intel

AIKIDO-2026-464233

duncanmcclean/statamic-cargo is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data AuthenticityGHSA-h6gx-wx52-cjj7 Published Yesterday

75

High Risk

This Affects:

PHPduncanmcclean/statamic-cargo
0.0.1 - 1.14.0
Fixed in 1.14.1
Are you affected? Scan for Free

TL;DR

The Mollie and Stripe payment gateways in Statamic Cargo complete checkout and mark an order as paid without comparing the provider reported payment amount and currency against the order's grand total. A customer who edits their cart after starting payment can pay less than the order total or pay in a different currency, and the order is still marked as paid. The fix compares the gateway reported amount and currency against the order before finishing checkout and deletes the pending order when that comparison throws PreventCheckout.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the Mollie or Stripe payment gateways.

Background info

duncanmcclean/statamic-cargo is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 1.14.0.

How to fix this

Upgrade the duncanmcclean/statamic-cargo library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform