DEV Community

Cover image for PolyShell Vulnerability Exposes Adobe Commerce and Magento to Remote Code Execution
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

PolyShell Vulnerability Exposes Adobe Commerce and Magento to Remote Code Execution

Summary

Sansec reports "PolyShell," an unrestricted file upload vulnerability (CVE-2025-20720) in Magento and Adobe Commerce that allows unauthenticated attackers to achieve remote code execution via the REST API.

Take Action:

If you are using Adobe Commerce and Magento Open Source, restrict web server access to the pub/media/custom_options/ directory to prevent the execution of uploaded malicious scripts. Since a production patch is currently not afailable, deploy a web application firewall to block exploit attempts in real-time.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)