CVE-2026-25524General(openmage / magento)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openmage magento systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger deserialization when processing `phar://` stream wrapper paths. OpenMage LTS uses these functions with potentially controllable file paths during image validation and media handling. An attacker who can upload a malicious phar file (disguised as an image) and trigger one of these functions with a `phar://` path can achieve arbitrary code execution. Version 20.17.0 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magento

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
magento

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-22: 104-2004-2104-22
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-201
General1
2026-04-212
Disclosure1General1
2026-04-221
Patch1
Full discourse4 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    ```json { "x": "🚨 HIGH: CVE-2026-25524 (CVSS 8.1)\nOpenMage LTS vulnerable to phar deserialization leading to RCE via malicious image uploads. Affects versions <20.17.0.\nUpgrade to 20.17.0 immediately.\n#CVE #Vulnerability #PatchNow #ThreatIntel", "linkedin": "🚨 HIGH SEVERITY ALERT\n\nCVE-2026-25524: OpenMage LTS Phar Deserialization Vulnerability\n\nCVSS Score: 8.1 (High)\nVector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n\nTHREAT SUMMARY:\nOpenMage LTS (Magento Long Term Support), a community-driven alternative to Magento Community Edition, contains a critical deserialization vulnerability that enables remote code execution.\n\nKEY DETAILS:\n• Affected Product: OpenMage LTS versions prior to 20.17.0\n• Vulnerability: PHP phar:// stream wrapper deserialization (CWE-502)\n• Attack Vector: Malicious phar files disguised as images\n• Functions Affected: getimagesize(), file_exists(), is_readable()\n• Impact: Arbitrary code execution with high confidentiality, integrity, and availability impact\n\nATTACK SCENARIO:\nAttackers can upload malicious phar files disguised as legitimate images. When OpenMage processes these files using vulnerable PHP functions with phar:// paths during image validation or media handling, deserialization occurs, leading to remote code execution.\n\nMITIGATION:\n✅ Upgrade to OpenMage LTS version 20.17.0 immediately\n✅ Review and restrict file upload capabilities\n✅ Implement strict file type validation\n✅ Monitor for suspicious phar:// stream wrapper usage in logs\n\nSOC teams should prioritize patching e-commerce platforms running OpenMage LTS and conduct retrospective analysis of uploaded media files.\n\n#CVE #Vulnerability #PatchNow #ThreatIntel #DFIR #CyberSecurity", "reddit": "**HIGH SEVERITY: CVE-2026-25524 - OpenMage LTS Phar Deserialization RCE**\n\n**CVSS Score:** 8.1 (High)\n**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\n**CWE:** CWE-502 (Deserialization of Untrusted Data)\n**Patched Version:** 20.17.0\n\n---\n\n**VULNERABILITY OVERVIEW**\n\nOpenMage LTS (Magento Long Term Support), an unofficial community-driven fork of Magento Community Edition, contains a critical vulnerability allowing remote code execution through phar deserialization. The vulnerability exists in versions prior to 20.17.0.\n\n**TECHNICAL DETAILS**\n\nThe vulnerability stems from improper handling of the phar:// stream wrapper in PHP. OpenMage LTS uses several native PHP functions during image validation and media handling operations:\n\n- getimagesize()\n- file_exists()\n- is_readable()\n\nWhen these functions process file paths containing the phar:// stream wrapper, PHP automatically deserializes metadata from phar archives. This behavior can be exploited if an attacker controls the file path parameter.\n\n**ATTACK CHAIN**\n\n1. Attacker crafts a malicious phar archive containing a serialized PHP object with magic methods (__destruct, __wakeup, etc.)\n2. Phar file is disguised as a legitimate image format (JPEG, PNG, etc.) to bypass basic file type checks\n3. Attacker uploads the malicious file through OpenMage's media upload functionality\n4. When OpenMage processes the uploaded file using vulnerable functions with a phar:// path, deserialization is triggered\n5.

    Post summary

    The post primarily urges users to apply the patch (upgrade to OpenMage LTS 20.17.0) after detailing the RCE vulnerability and mitigation steps.

    0000052
    26 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25524 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high le… https://www.cve.org/CVERecord?id=CVE-2026-25524 ----- Traducción: CVE-2026-25524 Mag… http://infoflow.cloud`

    Post summary

    The tweet announces the existence of CVE-2026-25524 for the Magento Long Term Support project and links to its CVE record, offering no technical or exploit information.

    0000027
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25524 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high le… https://www.cve.org/CVERecord?id=CVE-2026-25524

    Post summary

    The text references CVE-2026-25524 but provides no substantive details about the vulnerability, its exploitation, or mitigation.

    00000115
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25524 Arbitrary Code Execution via Phar Stream Deserialization ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25524 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-25524, briefly notes it involves arbitrary code execution via Phar stream deserialization, and links to a vulnerability details page, offering no further technical, exploit, or patch information.

    0000033
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenmagemagento---

Explore more