PT-2026-7635 · Medusajs · Medusajs
CVE-2025-69871
·
Publicado
2026-02-11
·
Atualizado
2026-02-12
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MedusaJS versions prior to 2.12.2
Description
A race condition exists in the
registerUsage() function within the promotion module. This function uses a non-atomic read-check-update process when managing promotion usage limits. This allows unauthenticated remote attackers to bypass these limits by sending multiple, simultaneous checkout requests. Successful exploitation can lead to unlimited redemptions of limited-use promotional codes and potential financial loss.Recommendations
Update to a version later than 2.12.2.
Exploit
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Medusajs