Back to CVE List

CVE-2026-25758

HIGH SEVERITY

Vulnerability Description

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their order by manipulating address ID parameters. This enables unauthorized access to other guests' personally identifiable information (PII) including names, addresses and phone numbers. The vulnerability bypasses existing ownership validation checks and affects all guest checkout transactions. This vulnerability is fixed in 4.10.3, 5.0.8, 5.1.10, 5.2.7, and 5.3.2.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-284
Source
GitHub
Vendor
rubygems
Product
spree_api

External References

Discussion (0)

Add Comment

No comments yet. Be the first!