GHSA-9ffx-f77r-756w · Severity: medium · Ecosystem: composer — Sylius has an Open Redirect via Referer Header
Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header directly when redirecting. The attack requires the victim to click a legitimate application link placed on an attacker-controlled page. The browser automatically sends the attacker's site as the Referer, and the application redirects back to it. This can be used for phishing or credential theft, as the redirect originates from a trusted domain. The severity varies by endpoint; public endpoints require no authentication and are trivially exploitable, while admin-only endpoints require an authenticated session but remain vulnerable if an admin follows a link from an external source such as email or chat. The issue is fixed in versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, 2.2.3 and above.
Conclusion & alert: CVE-2026-31819 is rated Low Risk (33.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-11 | 0.04% | 0.05% | +0.01% |
| 2 | 2026-03-12 | 0.05% | 0.04% | -0.01% |
| 3 | 2026-03-11 | — | 0.05% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.9 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-9ffx-f77r-756w · Severity: medium · Ecosystem: composer — Sylius has an Open Redirect via Referer Header
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sylius | sylius | < 1.9.12 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 1.10.0, < 1.10.16 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 1.11.0, < 1.11.17 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 1.12.0, < 1.12.23 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 1.13.0, < 1.13.15 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 1.14.0, < 1.14.18 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 2.0.0, < 2.0.16 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 2.1.0, < 2.1.12 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| sylius | sylius | >= 2.2.0, < 2.2.3 | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Sylius/Sylius/security/advisories/GHSA-9ffx-f77r-756w | Mitigation Vendor Advisory |