Unknown · Marcoscamara01 Ecommerce Template · CVE-2026-90896
**Name of the Vulnerable Software and Affected Versions**
MarcosCamara01 Ecommerce Template versions prior to commit 91e273c
**Description**
Missing authentication in the checkout session lookup handler allows a remote, unauthenticated attacker to retrieve full session objects. By providing a valid Stripe Checkout Session ID, an attacker can access sensitive buyer information, including name, email, phone number, billing address, amount paid, and internal `userId`. This occurs because the GET handler calls the `stripe.checkout.sessions.retrieve()` function and returns the data without verifying the user's authentication or ownership of the session. The session ID is often exposed in the browser URL after payment, making it susceptible to leakage via Referer headers, analytics tools, server access logs, and browser history. The affected API endpoint is GET '/api/stripe/checkout sessions'.
**Recommendations**
Update MarcosCamara01 Ecommerce Template to commit 91e273c or later.
As a temporary workaround, restrict access to the GET '/api/stripe/checkout sessions' endpoint to ensure only authenticated users can access it.