VYPR
Medium severity5.3NVD Advisory· Published Mar 10, 2026· Updated Jun 17, 2026

CVE-2026-31821

CVE-2026-31821

Description

Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers' carts by knowing the cart tokenValue. An attacker who obtains a cart tokenValue can add arbitrary items to another customer's cart. The endpoint returns the full cart representation in the response (HTTP 201). The issue is fixed in versions: 2.0.16, 2.1.12, 2.2.3 and above.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sylius/syliusPackagist
>= 2.0.0, < 2.0.162.0.16
sylius/syliusPackagist
>= 2.1.0, < 2.1.122.1.12
sylius/syliusPackagist
>= 2.2.0, < 2.2.32.2.3

Affected products

3
  • Sylius/Sylius2 versions
    cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*range: >=2.0.0,<2.0.16
    • (no CPE)range: >= 2.2.0, < 2.2.3
  • ghsa-coords
    Range: >= 2.0.0, < 2.0.16

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.

CVE-2026-31821 · Medium · VYPR