PT-2026-33797 · Openmage · Magento-Lts

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-25525

CVSS v3.1

4.9

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak blacklist filter (str replace('../', '', $input)) to prevent path traversal attacks. This filter can be bypassed using patterns like ..././ or ....//, which after the replacement still result in ../. An authenticated administrator can exploit this to read arbitrary files from the server filesystem. Version 20.17.0 patches the issue.

Fix

Path traversal

Incomplete List of Disallowed Inputs

Weakness Enumeration

Related Identifiers

CVE-2026-25525

Affected Products

Magento-Lts