vulns.co
/
GKData.io MCP

Spree · 1 min read

Spree: cart association must retain guest-possession checks

CVE-2026-94462 concerns a guest-cart ownership transition that required a signed-in customer but omitted the cart-possession check enforced by sibling operations. Account authentication and object lookup were treated as sufficient authority to claim an unowned cart, exposing existing checkout addresses and changing ownership.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: joining guest state to an account is a privileged ownership transition. Verify existing possession before mutation and response serialization; client-supplied proof helps only when the server checks it. The maintainer recommends backend releases 5.4.4 or 5.5.4 and says its storefront already supplied the required cart token.

Before reading

  • Basic object-level authorization and policy-composition concepts

Context and limits

  • Requires an authenticated store account, guest checkout enabled and an unassociated cart; address disclosure additionally requires stored checkout addresses. The advisory reports limited, recoverable cart reassignment and email changes, not anonymous access or account takeover.
  • The primary advisory supplies technical impact analysis; no production incident or independently reproduced outcome is established.
  • Published July 20, 2026 by damianlegawiec; reporter laijunyue is credited. The affected-version shorthand starts at 5.4.0 without an upper bound; use the stated patched branches rather than extrapolating. Software patch dates are unestablished and are not resource-edition dates.

Sources and provenance

  1. Spree guest-cart association access-control advisory (GHSA-4825-p4xm-pcf2) Spree · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software