
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31825 is a DQL (Doctrine Query Language) injection vulnerability in the Sylius open-source eCommerce framework for Symfony. The ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter API filters pass user-supplied order direction values directly to Doctrine's orderBy() without validation, enabling unauthenticated attackers to inject arbitrary DQL. It affects all Sylius versions up to and including 2.2.2 across multiple release branches (1.9.x through 2.2.x). The vulnerability was disclosed on March 9, 2026, and carries a CVSS v3.1 base score of 5.3 (Moderate) (GitHub Advisory, Sylius Advisory).
The root cause is improper neutralization of special elements in data query logic (CWE-943) and SQL/DQL injection (CWE-89). The vulnerable filters accept the order query parameter from API requests and pass the direction value (e.g., ASC or DESC) directly to Doctrine ORM's orderBy() method without whitelisting or sanitizing the input. An attacker can append additional DQL clauses to the direction value, as demonstrated by the proof-of-concept request: GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC. No authentication or special privileges are required — the attack is executable by any network-accessible client against the public-facing API endpoint (GitHub Advisory, Sylius Advisory).
Successful exploitation allows an unauthenticated attacker to inject arbitrary DQL into database queries, potentially enabling unauthorized read access to sensitive data stored in the Sylius database, including product pricing, customer records, and other confidential eCommerce information. The CVSS assessment reflects a low confidentiality impact with no integrity or availability impact, meaning the primary risk is unauthorized data disclosure rather than data modification or service disruption. Lateral movement within the application is not directly facilitated, but exposed customer or payment data could enable downstream attacks (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.047% (15th percentile), indicating a low near-term exploitation probability. No threat actor attribution has been reported. The attack requires no authentication and low complexity, which lowers the barrier for exploitation if a PoC is published (GitHub Advisory).
/api/v2/shop/products endpoint is accessible and accepts order query parameters.GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC or more complex DQL expressions to probe data exposure.orderBy()./api/v2/shop/products or other API endpoints with order parameters containing URL-encoded spaces, commas, or additional field references beyond simple ASC/DESC values (e.g., order[price]=ASC%2C%20variant.code%20DESC).order[] query parameter values; repeated requests to product listing API endpoints with varying injection payloads from the same IP.ORDER BY clauses with unexpected additional columns or expressions not matching standard filter fields (Sylius Advisory).Upgrade Sylius to one of the patched versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, or 2.2.3 (Sylius Advisory). For installations that cannot be patched immediately, implement a Symfony EventSubscriber (SanitizeOrderDirectionSubscriber) that intercepts API requests and whitelists the order direction parameter to only ASC or DESC before it reaches the vulnerable filters. Register the subscriber scoped to the /api/v2 route prefix using %sylius.security.new_api_route%, then clear the Symfony cache with bin/console cache:clear. Additionally, deploying a WAF rule to reject order[] parameter values containing characters beyond alphanumeric and basic direction keywords provides an additional layer of defense (GitHub Advisory).
The vulnerability was responsibly disclosed by Chris Alupului (@Neosprings) and Bartłomiej Nowiński (@bnBart), who are credited in the official Sylius security advisory (Sylius Advisory). Sylius published a security blog post covering the issue for both version 1.x and 2.x branches (Sylius Blog). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."