PT-2026-33796 · Openmage · Magento-Lts

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-25524

CVSS v3.1

8.1

High

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as getimagesize(), file exists(), and is readable() can trigger deserialization when processing phar:// stream wrapper paths. OpenMage LTS uses these functions with potentially controllable file paths during image validation and media handling. An attacker who can upload a malicious phar file (disguised as an image) and trigger one of these functions with a phar:// path can achieve arbitrary code execution. Version 20.17.0 patches the issue.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-25524

Affected Products

Magento-Lts