PT-2026-97017 · Spree · Spree
CVE-2026-94462
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spree versions 5.4.0 through 5.4.3
Spree versions 5.5.0 through 5.5.3
Description
An authenticated customer can associate an eligible guest cart with their own account and access the billing and shipping address data stored within that cart. This occurs because the
PATCH /api/v3/store/carts/:id/associate endpoint in Spree::Api::V3::Store::CartsController#associate uses the find cart for association() function to locate a cart by its prefixed id but fails to verify possession of the cart via a token. The prefixed id is generated using Sqids, a non-cryptographic and reversible encoding of the primary key, allowing an attacker to derive valid cart IDs offline. This issue is a form of broken access control known as Insecure Direct Object Reference (IDOR), where a user can access objects they are not authorized to view by manipulating the identifier. Exploitation requires a guest cart containing address data on a store that does not require login for checkout. This action can also disrupt the original guest's in-progress cart by reassigning ownership and overwriting the email address.Recommendations
Update Spree to version 5.4.4.
Update Spree to version 5.5.4.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spree