How to use this reference
Editorial lesson: define operation permissions independently from object ownership, and reconcile provider outcomes with local fulfillment state. The advisory recommends rejecting disallowed customer-context operations before effects. Maintainer release notes corroborate remediation in 2.1.16 and 2.2.9.
Before reading
- Basic application state machines, authorization and database transaction concepts
Context and limits
- Affected ranges are listed as 2.0.0 through versions before 2.1.16, and 2.2.0 through versions before 2.2.9.
- Impact is conditional on an enabled production API and a gateway exposing the relevant financial operations. The advisory explicitly excludes a plain default installation lacking that gateway.
- The maintainer describes financial-state inconsistency and consequent merchant-loss risk, not a documented production loss. This review does not independently verify those outcomes.
- TheMilek published the advisory; acirtautas is credited as finder. The reviewed advisory displays no known CVE; no identifier is inferred from secondary indexing.
- Both release pages display September 2 without a year in the reviewed rendering. Full patch dates are not asserted; the educational resource edition remains unknown.
Sources and provenance
- Shop API accepts arbitrary PaymentRequest actions, allowing a customer-triggered refund Sylius · reviewed 2026-10-03
- Sylius v2.1.16 security release Sylius · reviewed 2026-10-03
- Sylius v2.2.9 security release Sylius · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.