PT-2026-7635 · Medusajs · Medusajs

CVE-2025-69871

·

Published

2026-02-11

·

Updated

2026-02-12

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MedusaJS versions prior to 2.12.2
Description A race condition exists in the registerUsage() function within the promotion module. This function uses a non-atomic read-check-update process when managing promotion usage limits. This allows unauthenticated remote attackers to bypass these limits by sending multiple, simultaneous checkout requests. Successful exploitation can lead to unlimited redemptions of limited-use promotional codes and potential financial loss.
Recommendations Update to a version later than 2.12.2.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69871

Affected Products

Medusajs