Improper Neutralization of Alternate XSS Syntax in magento-lts - CVE-2026-42458
Published: May 5, 2026
magento-lts
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the administrator's browser.
The vulnerability exists due to improper neutralization of alternate XSS syntax in the Import -> Data Flow (profiles) run functionality when rendering a user-controlled filename in the run profile page. A remote user can upload or reference a specially crafted filename to execute arbitrary script in the administrator's browser.
The issue is reachable in the admin panel during Import profile execution.