Medium · 5.8 Node.js & npm GHSA-6j36-r6pr-59x4 CVE-2026-63472 GHSA-xhq9-whgq-49j5 CVE-2026-63459
Vendure Patches Three Vulnerabilities, Including a Critical Account Takeover Flaw
Vendure, an open-source headless commerce platform, has fixed three vulnerabilities: a critical account-takeover flaw in external authentication, a high-severity stored XSS in the admin dashboard, and a medium-severity Shop API filter bypass exposing hidden products and collections.
AI summary
Vendure, an open-source headless commerce platform built on Node.js, has disclosed and fixed three distinct vulnerabilities affecting its core and dashboard packages. The most severe issue allows account takeover through unverified external authentication, while the other two involve a stored cross-site scripting flaw in the admin dashboard and a filter bypass in the public Shop API that can expose non-public catalog data. All three issues have fixes available in current releases.
Three Separate Vulnerabilities Disclosed in Vendure
GitHub Advisory Database and NVD published three advisories for Vendure on the same day. CVE-2026-63472 (GHSA-6j36-r6pr-59x4) is a critical improper authentication issue in the external authentication flow of @vendure/core. CVE-2026-63459 (GHSA-xhq9-whgq-49j5) is a high-severity stored cross-site scripting (XSS) issue in @vendure/dashboard. CVE-2026-63461 (GHSA-xf65-r35x-wmmv) is a medium-severity information exposure issue in the Shop API of @vendure/core, allowing bypass of visibility guards on products, collections, and facets.
Technical Root Causes
CVE-2026-63472: In ExternalAuthenticationService.createCustomerAndUser, an existing customer account is located by email address and a newly presented external authentication method is attached to it without requiring that the email ownership be verified. In deployments using a custom external AuthenticationStrategy that forwards an email the provider has not verified, this allows an attacker to bind their external identity to a victim's existing account. CVE-2026-63459: RichTextDescriptionCell in the admin dashboard attempts to strip HTML markup by assigning an administrator-controlled description to a live DOM element's innerHTML and then reading textContent. Active markup can trigger an event handler during the innerHTML assignment, before textContent is read, resulting in script execution. CVE-2026-63461: The public Shop API's products, collections, and facets queries combine mandatory visibility guards (such as Product.enabled, Collection.isPrivate, Facet.isPrivate) with caller-supplied filters using a caller-controlled filterOperator. When filterOperator is set to OR, a predicate matching a hidden entity can bypass the visibility guard entirely.
Why It Matters
CVE-2026-63472 enables account takeover: an attacker who authenticates via a vulnerable external strategy using a victim's email address can gain access to that victim's orders, addresses, and personal information, and perform account changes or place orders as the victim. CVE-2026-63459 allows a lower-privilege administrator to store malicious markup in descriptions shown in the Products, Collections, Promotions, Payment Methods, or Shipping Methods lists. The script executes when another administrator views the affected row, potentially compromising that administrator's session and enabling cross-privilege or cross-channel administrative actions. CVE-2026-63461 allows an unauthenticated caller to retrieve disabled products and private collections or facets that should not be publicly visible, exposing catalog data that merchants intended to keep hidden.
Who Is Affected
CVE-2026-63472 only affects deployments using a custom external AuthenticationStrategy that forwards an email address without guaranteeing the provider has verified ownership of it. Native-only email and password deployments, and external strategies that always require provider-verified email ownership, are not affected. New-account creation for an email address not already in use remains unaffected. CVE-2026-63459 affects any Vendure deployment using the admin dashboard where administrators with varying privilege levels can edit descriptions for products, collections, promotions, payment methods, or shipping methods. CVE-2026-63461 affects any deployment exposing the public Shop API with disabled products, private collections, or private facets, since these can be queried by unauthenticated users.
Affected Versions
@vendure/core versions prior to 3.7.0 are affected by the external authentication account takeover (CVE-2026-63472). @vendure/dashboard versions prior to 3.6.5 are affected by the stored XSS issue (CVE-2026-63459). @vendure/core versions from 1.0.0 up to (but not including) 3.6.5 are affected by the Shop API filter bypass (CVE-2026-63461).
Fixes Available
The external authentication account takeover (CVE-2026-63472) is fixed in @vendure/core version 3.7.0. The stored XSS issue (CVE-2026-63459) is fixed in @vendure/dashboard version 3.6.5. The Shop API filter bypass (CVE-2026-63461) is also fixed in @vendure/core version 3.6.5.
Recommended Action
Update @vendure/core to version 3.7.0 or later to address both the account takeover and Shop API filter bypass issues. Update @vendure/dashboard to version 3.6.5 or later to address the stored XSS issue. Deployments using a custom external AuthenticationStrategy should additionally review whether their provider verifies email ownership before relying on email-based account linking. Deployments relying on hidden or private catalog entities should verify, after patching, that disabled products and private collections or facets are no longer retrievable via the Shop API.
PatchBriefing score
5.8 / 10 · Medium
Official CVSS: 9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Why this score
The three vulnerabilities carry different severity levels. CVE-2026-63472 scores 9.1 (critical) because it allows an unauthenticated attacker to take over a victim's account remotely without user interaction, exposing orders, addresses, and personal information. CVE-2026-63459 scores 8.7 (high) due to its stored XSS nature, which can compromise an administrator's session, though it requires an authenticated lower-privilege administrator to store the payload and another administrator to view it. CVE-2026-63461 scores 5.3 (medium), reflecting a confidentiality-only impact limited to exposure of non-public catalog data, with no integrity or availability impact. No public exploit code or evidence of exploitation in the wild has been reported for any of the three issues.
Affected versions
- @vendure/core < 3.7.0
- vulnerable
- ≥ 3.7.0
- patched
- @vendure/dashboard < 3.6.5
- vulnerable
- ≥ 3.6.5
- patched
- @vendure/core >= 1.0.0, < 3.6.5
- vulnerable
- ≥ 3.6.5
- patched
Reported fixes
The external authentication account takeover (CVE-2026-63472) is fixed in @vendure/core version 3.7.0. The stored XSS issue (CVE-2026-63459) is fixed in @vendure/dashboard version 3.6.5. The Shop API filter bypass (CVE-2026-63461) is also fixed in @vendure/core version 3.6.5.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
-
GitHub Advisory Database database
-
NVD (NIST) database
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email