PT-2026-97017 · Spree · Spree

CVE-2026-94462

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spree versions 5.4.0 through 5.4.3 Spree versions 5.5.0 through 5.5.3
Description An authenticated customer can associate an eligible guest cart with their own account and access the billing and shipping address data stored within that cart. This occurs because the PATCH /api/v3/store/carts/:id/associate endpoint in Spree::Api::V3::Store::CartsController#associate uses the find cart for association() function to locate a cart by its prefixed id but fails to verify possession of the cart via a token. The prefixed id is generated using Sqids, a non-cryptographic and reversible encoding of the primary key, allowing an attacker to derive valid cart IDs offline. This issue is a form of broken access control known as Insecure Direct Object Reference (IDOR), where a user can access objects they are not authorized to view by manipulating the identifier. Exploitation requires a guest cart containing address data on a store that does not require login for checkout. This action can also disrupt the original guest's in-progress cart by reassigning ownership and overwriting the email address.
Recommendations Update Spree to version 5.4.4. Update Spree to version 5.5.4.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94462
GHSA-4825-P4XM-PCF2

Affected Products

Spree