GHSA-wh92-6q6g-px7j
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-54236, https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397, https://github.com/magento/magento2, https://helpx.adobe.com/security/products/magento/apsb25-88.html, https://nullsecurityx.codes/cve-2025-54236-sessionreaper-unauthenticated-rce-in-magento, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54236
