CVE-2026-53637
Deferred Deferred - Pending Action

Improper Workflow Enforcement in Sylius Cart FormComponent

Vulnerability report for CVE-2026-53637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
sylius sylius From 2.0.0 (inc) to 2.0.17 (inc)
sylius sylius From 2.1.0 (inc) to 2.1.14 (inc)
sylius sylius From 2.2.0 (inc) to 2.2.5 (inc)
sylius sylius 2.0.18
sylius sylius 2.1.15
sylius sylius 2.2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-672 The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
CWE-841 The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Sylius e-commerce framework allows an authenticated user to modify or delete an already-completed order. It occurs in the Cart FormComponent where a LiveComponent fails to detect changes to the order's state after completion. If a user finalizes payment or an admin updates the order status while the cart page remains open, the system incorrectly allows cart modifications, leading to potential data corruption or loss.

Detection Guidance

This vulnerability is specific to the Sylius e-commerce framework and cannot be detected via general network or system commands. Instead, check if your Sylius application is running a vulnerable version (2.0.0-2.0.17, 2.1.0-2.1.14, or 2.2.0-2.2.5) by inspecting the installed version in your project's composer.lock or composer.json files.

Impact Analysis

An attacker could exploit this to alter or delete completed orders, causing financial discrepancies, loss of customer data, or disruption of order fulfillment. Customers might lose purchased items or face incorrect billing. Businesses could suffer reputational damage or compliance violations due to inaccurate order records.

Compliance Impact

This vulnerability could lead to violations of GDPR (data integrity, right to erasure) or HIPAA (unauthorized data alteration) by allowing unauthorized changes to completed orders. It risks exposing or corrupting sensitive customer data, potentially resulting in legal penalties or loss of trust.

Mitigation Strategies

Upgrade Sylius to a patched version (2.0.18, 2.1.15, or 2.2.6) immediately. If upgrading is not feasible, apply the workaround by copying the patched FormComponent into your application's src directory and override the sylius_shop.twig.component.cart.form service definition to use the patched class.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart