Intel

AIKIDO-2026-865495

shopware/core is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)GHSA-6qhw-38wm-7g7h Published 2 days ago

96

Critical Risk

This Affects:

PHPshopware/core
6.5.4.0 - 6.6.10.22
Fixed in 6.6.10.23
6.7.0.0 - 6.7.13.0
Fixed in 6.7.13.1
Are you affected? Scan for Free

TL;DR

shopware/core App Scripts can bypass their intended sandbox restrictions. A malicious or compromised App that is installed and activated can execute arbitrary PHP functions and operating-system commands with the privileges of the PHP/web-server process. That can expose configuration and credentials, change writable files, reach internal services, or disrupt the shop.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and have Apps installed and activated.

Background info

shopware/core is vulnerable to Remote Code Execution (RCE) in versions 6.5.4.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.

How to fix this

Upgrade the shopware/core and/or the shopware/platform library to the patch version.