Intel

AIKIDO-2026-865495

shopware/core is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)GHSA-6qhw-38wm-7g7h Published Aug 26, 2026

96

Critical Risk

This Affects:

PHPshopware/core
6.5.4.0 - 6.6.10.22
Fixed in 6.6.10.23
6.7.0.0 - 6.7.13.0
Fixed in 6.7.13.1
Are you affected? Scan for Free

TL;DR

shopware/core App Scripts can bypass their intended sandbox restrictions. A malicious or compromised App that is installed and activated can execute arbitrary PHP functions and operating-system commands with the privileges of the PHP/web-server process. That can expose configuration and credentials, change writable files, reach internal services, or disrupt the shop.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and have Apps installed and activated.

Background info

shopware/core is vulnerable to Remote Code Execution (RCE) in versions 6.5.4.0 - 6.6.10.22 and 6.7.0.0 - 6.7.13.0.

How to fix this

Upgrade the shopware/core and/or the shopware/platform library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform