
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31820 is an authenticated Insecure Direct Object Reference (IDOR) vulnerability in Sylius, an open-source eCommerce framework built on Symfony. The flaw exists in multiple shop LiveComponents — specifically the Checkout address FormComponent, Cart WidgetComponent, and Cart SummaryComponent — where unvalidated resource IDs are accepted via #[LiveArg] parameters without ownership verification. Affected versions include Sylius 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2. The vulnerability was published on March 9, 2026 (GitHub Advisory) and March 10, 2026 (NVD), and carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Sylius Advisory).
The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): Symfony LiveComponent #[LiveArg] parameters are fully user-controlled and not protected by the @checksum mechanism that guards #[LiveProp] values. Three vulnerable actions exist: (1) addressFieldUpdated in the Checkout address FormComponent accepts an addressId and calls ->find() without verifying the address belongs to the authenticated customer; (2) refreshCart in the Cart WidgetComponent accepts a cartId and loads any order directly from the repository; (3) refreshCart in the Cart SummaryComponent similarly loads any order by ID. Because the sylius_order table stores both active carts (state=cart) and completed orders (state=new/fulfilled) in a shared ID space, the cart IDOR exposes data across all order states, not just active carts (GitHub Advisory, Sylius Advisory).
A successfully authenticated attacker can enumerate sequential or guessable order/address IDs to access other customers' personally identifiable information (PII) and financial data. The Checkout address component exposes first name, last name, company, phone number, street, city, postcode, and country of arbitrary users. The Cart Widget and Cart Summary components expose order totals, item counts, subtotals, discounts, shipping costs, and tax details for both active carts and completed orders across the entire customer base. There is no integrity or availability impact, but the confidentiality breach is high and could facilitate targeted phishing, fraud, or regulatory violations (e.g., GDPR) (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires only a low-privilege authenticated account (any registered shop customer), making it accessible to a broad attacker population. The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was responsibly disclosed by Peter Stöckli (@p-) and Man Yue Mo (@m-y-mo) of the GitHub Security Lab (Sylius Advisory).
#[LiveArg] parameters (typically a POST to a Symfony UX LiveComponent route).addressFieldUpdated action of the Checkout address FormComponent, substituting the addressId LiveArg with sequential integers (e.g., 1, 2, 3, ...) to retrieve other users' address PII.refreshCart action of the Cart WidgetComponent or Cart SummaryComponent, substituting the cartId LiveArg with sequential integers to retrieve order totals, item counts, discounts, shipping costs, and tax details for arbitrary orders — including completed orders./_components/sylius_shop:checkout:address:form or /_components/sylius_shop:cart:widget) from a single authenticated session, with rapidly incrementing addressId or cartId values in the request body.addressFieldUpdated, refreshCart) with sequential or enumerated integer IDs from the same user session or IP address.->find() calls on the address or order repository from a single customer context within a short time window.Upgrade Sylius to the patched versions: 2.0.16 (for the 2.0.x line), 2.1.12 (for the 2.1.x line), or 2.2.3 (for the 2.2.x line). For teams unable to upgrade immediately, the advisory provides a detailed workaround involving overriding the three vulnerable LiveComponent classes at the project level to add ownership validation: use findOneByCustomer() instead of find() in the address FormComponent, and ignore the user-supplied cartId in both cart components by always loading the cart from the session context. After applying overrides, register the new service definitions in config/services.yaml and clear the Symfony cache with php bin/console cache:clear (Sylius Advisory, GitHub Advisory).
The vulnerability was responsibly disclosed by Peter Stöckli (@p-) and Man Yue Mo (@m-y-mo) of the GitHub Security Lab, who are credited in the official Sylius advisory. Sylius published a security blog post alongside the advisory. No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability tracking (Sylius Blog, Sylius Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."