目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-103831— TrueLayer Magento 2 插件不安全的反序列化漏洞

一分钟漏洞结论

影响对象
TrueLayer TrueLayer Magento 2 Plugin
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

CVE-2026-103831:TrueLayer Magento 2 插件中的 Psr16CacheAdapter 组件存在不安全的反序列化漏洞。该漏洞源于在从缓存中检索数据时,直接使用了 PHP 原生的 函数,且未对允许反序列化的类进行任何限制。如果攻击者已经能够将篡改后的数据写入 Magento 所使用的缓存后端(例如 Redis 或 Memcached),则可以注入特制的 PHP 对象并触发其反序列化,进而利用应用程序环境中可用的“gadget 链”实现任意代码执行。因此,成功利用此漏洞的前提条件是攻击者具

CVSS 7.5 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-103831 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Insecure deserialization in the TrueLayer Magento 2 plugin
来源: CVE Program / CVE List V5
Vulnerability Description
CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write manipulated data to the cache backend used by Magento—such as Redis or Memcached—could inject specially crafted PHP objects and trigger their deserialization, potentially leading to arbitrary code execution via gadget strings available in the application environment. Exploitation therefore requires a prerequisite condition that allows writing to the cache infrastructure, either through access to the local file system or to a cache infrastructure accessible from the Magento environment.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
TrueLayer TrueLayer Magento 2 Plugin versions 2.4.0 through 2.4.2. -

二、漏洞 CVE-2026-103831 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-103831 的情报信息

请登录查看更多情报信息。

CVE-2026-103831 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-103831

暂无评论


发表评论