DEV Community

Cover image for PolyShell Vulnerability Exposes Adobe Commerce and Magento to Remote Code Execution
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

PolyShell Vulnerability Exposes Adobe Commerce and Magento to Remote Code Execution

Summary

Sansec reports "PolyShell," an unrestricted file upload vulnerability (CVE-2025-20720) in Magento and Adobe Commerce that allows unauthenticated attackers to achieve remote code execution via the REST API.

Take Action:

If you are using Adobe Commerce and Magento Open Source, restrict web server access to the pub/media/custom_options/ directory to prevent the execution of uploaded malicious scripts. Since a production patch is currently not afailable, deploy a web application firewall to block exploit attempts in real-time.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)