Path traversal in Shopware - #VU145366
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to path traversal in the media update functionality when updating a media file extension. A remote privileged user can modify the media file extension to write files outside the intended media directory to execute arbitrary code.
Exploitation requires the media:update privilege and may lead to full compromise of the shop in affected configurations.