vulns.co
/
GKData.io MCP

GitHub Security Lab · 2 min read

Sylius: component integrity does not authorize referenced objects

CVE-2026-31820 concerns client-supplied component action arguments used to load objects without ownership checks. Property checksums did not cover those arguments. GHSL describes cross-customer address disclosure in tested version 2.2.3-dev; the maintainer additionally identifies disclosure of cart and order financial summaries.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: integrity protection on component state does not establish authority over every referenced object. Bind each lookup to the current customer or authorized session context. The maintainer lists fixes in 2.0.16, 2.1.12 and 2.2.3 and supplies a project-level authorization workaround; its correctness for customized deployments is not established here.

Before reading

  • Basic object-level access-control concepts
  • Familiarity with web request and response processing

Context and limits

  • Requires an authenticated customer using affected shop components. The demonstrated research case concerns another customer’s address; the maintainer’s broader scope also covers order summaries because active carts and completed orders share a data model.
  • The research describes controlled cross-customer disclosure, not an observed customer breach. The reviewed evidence does not establish write access, payment execution or account takeover.
  • GHSL records reporting on February 19, 2026 and maintainer-advisory publication on March 9; detailed research was published March 17. Exact product release dates are not established by these sources. Resource edition release remains unknown.
  • The development snapshot tested by GHSL is distinct from the final 2.2.3 release named as patched by the maintainer. No contradiction or remediation failure is inferred from the similar labels.
  • The byline is Man Yue Mo. Discovery is credited to GitHub Security Lab Taskflow Agent, with manual verification by Peter Stöckli and Man Yue Mo; the maintainer credits both and the GHSL team. Learning prerequisites are editorial.

Sources and provenance

  1. GHSL-2026-055: Unauthorized access to PII in Sylius - CVE-2026-31820 GitHub Security Lab · reviewed 2026-10-03
  2. IDOR in Cart and Checkout LiveComponents Sylius · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software