GHSA-6qhw-38wm-7g7h GHSA-xj2c-8fw5-mr6m GHSA-xrcf-c96g-q5hr GHSA-p37c-pm9p-7vm5 GHSA-p67w-3mq7-rw2g GHSA-4wpv-5fvv-c3xp GHSA-fgjq-45xv-rj8r GHSA-674c-5376-96rv GHSA-f497-xgx3-22hq GHSA-rrc3-p9vx-5373
Shopware 6.6.10.23 and 6.7.13.1 fix App Script sandbox escape, admin takeover and other flaws
Shopware's 6.6.10.23 and 6.7.13.1 releases fix ten flaws, including a critical App Script sandbox escape, admin account takeover via Host-header poisoning, SQL injection, SSRF and path traversal. Update immediately.
What happened
Shopware's 6.6.10.23 and 6.7.13.1 releases address ten advisories. The most severe, GHSA-6qhw-38wm-7g7h (CVSS 9.6), lets a malicious or compromised App installed and activated on Shopware escape its sandbox and execute arbitrary PHP and operating-system commands with the web server's permissions. That could expose configuration or credentials, modify files the process can write, reach internal services, or disrupt the shop. A second critical advisory, GHSA-xj2c-8fw5-mr6m (CVSS 9.3), allows an unauthenticated attacker to poison an administrator password-reset link through the Host header; if the administrator opens the manipulated link, the attacker can take over the account.
GHSA-xrcf-c96g-q5hr (CVSS 9.1) lets a malicious or compromised App run arbitrary SQL through crafted custom-entity definitions. The remaining advisories cover pre-authentication SQL injection in the Store API, path traversal through writable media file extensions, ACL role mass assignment, server-side request forgery, disclosure of unapproved product reviews, and missing rate limiting on guest document downloads. Shopware has not stated that any of these flaws is being exploited, and none is listed in CISA KEV.
Who is affected
The affected version ranges vary by advisory. Shopware lists ranges such as 6.5.4.0 through 6.6.10.22, 6.7.0.0 through 6.7.13.0, and 6.7.1.0 through 6.7.13.0; several advisories apply to all versions before 6.6.10.23. Sales Channel access keys are commonly exposed by design in headless Store API integrations, so the Store API SQL injection should be treated as reachable without credentials in many deployments. The fixed releases are Shopware 6.6.10.23 and Shopware 6.7.13.1, depending on the advisory.
What to do now
- Update to Shopware 6.7.13.1 if you are running 6.7.0.0 through 6.7.13.0. Update to Shopware 6.6.10.23 if you are running a version before 6.6.10.23. If you are on an older release, Shopware advises upgrading to a supported patched release.
- If you cannot patch immediately, apply Shopware's workarounds: enable Symfony trusted-host validation or reject unexpected Host headers at the web server or reverse proxy; install and update Apps only from trusted sources; restrict outbound access and block private, loopback, link-local and cloud-metadata address ranges; restrict Store API exposure and monitor Store API and database logs; restrict media import and media update permissions to trusted users; and apply rate limiting to guest document-download requests at the reverse proxy or WAF.
- After updating, review installed Apps, custom entity definitions, administrator accounts and role assignments, and remove access that is not required.
How to detect it
Shopware has not published indicators of compromise. Practical checks supported by the advisories: review Store API and database logs for unexpected requests or anomalous SQL activity; inventory installed Apps and custom entity definitions; review media update and media import permissions; and watch for repeated guest authentication attempts against the same document download link from one IP address.
Beyond the patch
Shopware usually sits in the revenue path, so these flaws are commercial risk as much as technical risk. Injection and authentication issues are exactly what Implementation & Assessment Services penetration tests and hardening reviews are designed to find before an attacker does. Tracking which vendors you run and how quickly they fix issues is Supply Chain Defense & Third-Party Risk.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| GHSA-6qhw-38wm-7g7h Shopware | 6.5.4.0 – < 6.6.10.23 6.5.4.0 – < 6.6.10.23 6.7.0.0 – < 6.7.13.1 6.7.0.0 – < 6.7.13.1 | 6.6.10.23 6.7.13.1 3, 6.7.13.1 |
| GHSA-xj2c-8fw5-mr6m Shopware | – < 6.6.10.23 – < 6.6.10.23 6.7.0.0 – < 6.7.13.1 6.7.0.0 – < 6.7.13.1 | 6.6.10.23 6.7.13.1 3, 6.7.13.1 |
| GHSA-xrcf-c96g-q5hr, GHSA-fgjq-45xv-rj8r, GHSA-rrc3-p9vx-5373 Shopware | 6.7.0.0 – < 6.7.13.1 6.7.0.0 – < 6.7.13.1 – < 6.6.10.23 – < 6.6.10.23 | 6.7.13.1 6.6.10.23 3, 6.7.13.1 |
| GHSA-p37c-pm9p-7vm5, GHSA-4wpv-5fvv-c3xp Shopware | 6.7.0.0 – < 6.7.13.1 – < 6.6.10.23 6.7.0.0 – < 6.7.13.1 – < 6.6.10.23 | 6.7.13.1 6.6.10.23 3, 6.7.13.1 |
| GHSA-p67w-3mq7-rw2g Shopware | 6.7.1.0 – < 6.7.13.1 6.7.1.0 – < 6.7.13.1 | 6.7.13.1 6.7.13.1 |
| GHSA-674c-5376-96rv Shopware | 6.7.0.0 – < 6.7.13.1 6.7.0.0 – < 6.7.13.1 6.6.6.0 – < 6.6.10.23 6.6.6.0 – < 6.6.10.23 6.5.8.15 – < 6.6.10.23 6.5.8.15 – < 6.6.10.23 | 6.7.13.1 6.6.10.23 3, 6.7.13.1 |
| GHSA-f497-xgx3-22hq Shopware | 6.7.0.0 – < 6.7.13.1 6.7.0.0 – < 6.7.13.1 6.6.10.0 – < 6.6.10.23 6.6.10.0 – < 6.6.10.23 | 6.7.13.1 6.6.10.23 3, 6.7.13.1 |
References
Vendor advisory
- App Script sandbox escape allows arbitrary PHP and OS command execution
- Admin account takeover via Host-header password-reset poisoning
- Stored SQL/DDL Injection via Custom Entity Field Names (App Manifest)
- Pre-authentication SQL injection in Store API
- Path traversal via writable media.fileExtension leads to remote code execution (single …
- Privilege escalation via aclRoles mass assignment remains possible after CVE-2026-48010…
- SSRF in Shopware media URL import via DNS rebinding bypass of FileUrlValidator IP valid…
- Unauthenticated disclosure of unapproved product reviews via nested store-api associations