Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-54159

ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
Back to all
CVE

CVE-2026-54159

ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

PrestaShop psfacetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the psfacetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal filter-block cache where it is serialized and later read back with a raw native unserialize() in src/Filters/Block.php. By crafting that value, an unauthenticated attacker can smuggle a malicious serialized PHP object into the cache, and when it is deserialized, a gadget chain writes an arbitrary PHP file inside the modules/ps_facetedsearch/ directory, which is then used as a webshell to run commands on the server. This issue is fixed in version 4.0.4.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
10
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/PrestaShop/psfacetedsearch/releases/tag/v4.0.4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54159.json, https://github.com/PrestaShop/psfacetedsearch/security/advisories/GHSA-m5f5-28qr-9g9r, https://nvd.nist.gov/vuln/detail/CVE-2026-54159, https://github.com/PrestaShop/ps_facetedsearch/commit/9ca839fac68a60641d8187a3ff9730ab09af33cb

Severity

10

CVSS Score
0
10

Basic Information

Base CVSS
10
EPSS Probability
0.0075%
EPSS Percentile
0.53534%
Introduced Version
41cbc9f08cc074ec09f736099579aac73c19d7b2
Fix Available
08d80f46ef101389a8128232b1a208142c28a718

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading