Intel

AIKIDO-2026-724507

magento/magento-cloud-metapackage is vulnerable to Code Injection

Code Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Yesterday

98

Critical Risk

This Affects:

Are you affected? Scan for Free

TL;DR

magento/magento-cloud-metapackage pulls Adobe Commerce, which ships Magento's template system and GraphQL stack. An unauthenticated requester can inject PHP through styles properties on GraphQL requests, persist it via a failure report, then have it execute when Magento renders the Payment Transaction Failed Reminder email. Delivery of that email is not required because the payload runs during render. Successful exploitation leads to remote code execution and lets a backdoor be installed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and GraphQL is reachable.

Background info

magento/magento-cloud-metapackage is vulnerable to Code Injection in versions 0.0.1 - 2.4.9.

How to fix this

Upgrade the magento/magento-cloud-metapackage library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform