Skip to content

GHSA-6qhw-38wm-7g7h GHSA-xj2c-8fw5-mr6m GHSA-xrcf-c96g-q5hr GHSA-p37c-pm9p-7vm5 GHSA-p67w-3mq7-rw2g GHSA-4wpv-5fvv-c3xp GHSA-fgjq-45xv-rj8r GHSA-674c-5376-96rv GHSA-f497-xgx3-22hq GHSA-rrc3-p9vx-5373

Shopware 6.6.10.23 and 6.7.13.1 fix App Script sandbox escape, admin takeover and other flaws

Critical 9.6 Vendor: Shopware Published

Shopware's 6.6.10.23 and 6.7.13.1 releases fix ten flaws, including a critical App Script sandbox escape, admin account takeover via Host-header poisoning, SQL injection, SSRF and path traversal. Update immediately.

What happened

Shopware's 6.6.10.23 and 6.7.13.1 releases address ten advisories. The most severe, GHSA-6qhw-38wm-7g7h (CVSS 9.6), lets a malicious or compromised App installed and activated on Shopware escape its sandbox and execute arbitrary PHP and operating-system commands with the web server's permissions. That could expose configuration or credentials, modify files the process can write, reach internal services, or disrupt the shop. A second critical advisory, GHSA-xj2c-8fw5-mr6m (CVSS 9.3), allows an unauthenticated attacker to poison an administrator password-reset link through the Host header; if the administrator opens the manipulated link, the attacker can take over the account.

GHSA-xrcf-c96g-q5hr (CVSS 9.1) lets a malicious or compromised App run arbitrary SQL through crafted custom-entity definitions. The remaining advisories cover pre-authentication SQL injection in the Store API, path traversal through writable media file extensions, ACL role mass assignment, server-side request forgery, disclosure of unapproved product reviews, and missing rate limiting on guest document downloads. Shopware has not stated that any of these flaws is being exploited, and none is listed in CISA KEV.

Who is affected

The affected version ranges vary by advisory. Shopware lists ranges such as 6.5.4.0 through 6.6.10.22, 6.7.0.0 through 6.7.13.0, and 6.7.1.0 through 6.7.13.0; several advisories apply to all versions before 6.6.10.23. Sales Channel access keys are commonly exposed by design in headless Store API integrations, so the Store API SQL injection should be treated as reachable without credentials in many deployments. The fixed releases are Shopware 6.6.10.23 and Shopware 6.7.13.1, depending on the advisory.

What to do now

  1. Update to Shopware 6.7.13.1 if you are running 6.7.0.0 through 6.7.13.0. Update to Shopware 6.6.10.23 if you are running a version before 6.6.10.23. If you are on an older release, Shopware advises upgrading to a supported patched release.
  2. If you cannot patch immediately, apply Shopware's workarounds: enable Symfony trusted-host validation or reject unexpected Host headers at the web server or reverse proxy; install and update Apps only from trusted sources; restrict outbound access and block private, loopback, link-local and cloud-metadata address ranges; restrict Store API exposure and monitor Store API and database logs; restrict media import and media update permissions to trusted users; and apply rate limiting to guest document-download requests at the reverse proxy or WAF.
  3. After updating, review installed Apps, custom entity definitions, administrator accounts and role assignments, and remove access that is not required.

How to detect it

Shopware has not published indicators of compromise. Practical checks supported by the advisories: review Store API and database logs for unexpected requests or anomalous SQL activity; inventory installed Apps and custom entity definitions; review media update and media import permissions; and watch for repeated guest authentication attempts against the same document download link from one IP address.

Beyond the patch

Shopware usually sits in the revenue path, so these flaws are commercial risk as much as technical risk. Injection and authentication issues are exactly what Implementation & Assessment Services penetration tests and hardening reviews are designed to find before an attacker does. Tracking which vendors you run and how quickly they fix issues is Supply Chain Defense & Third-Party Risk.

Affected and fixed versions

ProductAffectedFixed in
GHSA-6qhw-38wm-7g7h
Shopware
6.5.4.0 – < 6.6.10.23
6.5.4.0 – < 6.6.10.23
6.7.0.0 – < 6.7.13.1
6.7.0.0 – < 6.7.13.1
6.6.10.23
6.7.13.1
3, 6.7.13.1
GHSA-xj2c-8fw5-mr6m
Shopware
– < 6.6.10.23
– < 6.6.10.23
6.7.0.0 – < 6.7.13.1
6.7.0.0 – < 6.7.13.1
6.6.10.23
6.7.13.1
3, 6.7.13.1
GHSA-xrcf-c96g-q5hr, GHSA-fgjq-45xv-rj8r, GHSA-rrc3-p9vx-5373
Shopware
6.7.0.0 – < 6.7.13.1
6.7.0.0 – < 6.7.13.1
– < 6.6.10.23
– < 6.6.10.23
6.7.13.1
6.6.10.23
3, 6.7.13.1
GHSA-p37c-pm9p-7vm5, GHSA-4wpv-5fvv-c3xp
Shopware
6.7.0.0 – < 6.7.13.1
– < 6.6.10.23
6.7.0.0 – < 6.7.13.1
– < 6.6.10.23
6.7.13.1
6.6.10.23
3, 6.7.13.1
GHSA-p67w-3mq7-rw2g
Shopware
6.7.1.0 – < 6.7.13.1
6.7.1.0 – < 6.7.13.1
6.7.13.1
6.7.13.1
GHSA-674c-5376-96rv
Shopware
6.7.0.0 – < 6.7.13.1
6.7.0.0 – < 6.7.13.1
6.6.6.0 – < 6.6.10.23
6.6.6.0 – < 6.6.10.23
6.5.8.15 – < 6.6.10.23
6.5.8.15 – < 6.6.10.23
6.7.13.1
6.6.10.23
3, 6.7.13.1
GHSA-f497-xgx3-22hq
Shopware
6.7.0.0 – < 6.7.13.1
6.7.0.0 – < 6.7.13.1
6.6.10.0 – < 6.6.10.23
6.6.10.0 – < 6.6.10.23
6.7.13.1
6.6.10.23
3, 6.7.13.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.