How to use this reference
Editorial lesson: integrity protection on component state does not establish authority over every referenced object. Bind each lookup to the current customer or authorized session context. The maintainer lists fixes in 2.0.16, 2.1.12 and 2.2.3 and supplies a project-level authorization workaround; its correctness for customized deployments is not established here.
Before reading
- Basic object-level access-control concepts
- Familiarity with web request and response processing
Context and limits
- Requires an authenticated customer using affected shop components. The demonstrated research case concerns another customer’s address; the maintainer’s broader scope also covers order summaries because active carts and completed orders share a data model.
- The research describes controlled cross-customer disclosure, not an observed customer breach. The reviewed evidence does not establish write access, payment execution or account takeover.
- GHSL records reporting on February 19, 2026 and maintainer-advisory publication on March 9; detailed research was published March 17. Exact product release dates are not established by these sources. Resource edition release remains unknown.
- The development snapshot tested by GHSL is distinct from the final 2.2.3 release named as patched by the maintainer. No contradiction or remediation failure is inferred from the similar labels.
- The byline is Man Yue Mo. Discovery is credited to GitHub Security Lab Taskflow Agent, with manual verification by Peter Stöckli and Man Yue Mo; the maintainer credits both and the GHSL team. Learning prerequisites are editorial.
Sources and provenance
- GHSL-2026-055: Unauthorized access to PII in Sylius - CVE-2026-31820 GitHub Security Lab · reviewed 2026-10-03
- IDOR in Cart and Checkout LiveComponents Sylius · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.