Key Facts

Sansec reports active exploitation of StyleSmuggler, an unauthenticated remote-code-execution chain affecting Magento and Adobe Commerce. Its testing reproduced the chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations.

Technical Details

Sansec says the attack injects PHP into Magento’s template system and triggers execution during rendering of a failed-payment email. The research describes follow-on backdoors masquerading as Linux processes and additional web-shell activity on compromised stores.

Impact & Mitigation

Merchants should treat exposed stores as at risk, investigate Sansec’s published indicators, and rotate Magento credentials if suspicious processes are found. Until an official vendor fix is available, Sansec says temporarily disabling GraphQL can reduce exposure.

Sources

By Allan