Vendure 是一个开源的无头(headless)电商平台。在 3.6.5 版本之前,其公共 Shop API 中的产品(products)、集合(collections)和分面(facets)查询会将强制可见性检查与由调用方提供的过滤条件相结合,并使用由调用方控制的 (过滤运算符)。当 设置为 时,一个匹配隐藏实体的谓词条件可以绕过 、 或 的可见性保护。因此,未认证的调用者可以获取到已禁用的产品以及私有的集合或分面。该问题已在 3.6.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63472 | 9.1 CRITICAL | Vendure: External-authentication account takeover: external login linked to a pre-existing |
| CVE-2026-63459 | 8.7 HIGH | Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity |
| CVE-2026-63460 | 7.5 HIGH | Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends |
No comments yet