{"id":"CVE-2026-31821","summary":"Sylius is Missing Authorization in API v2 Add Item Endpoint","details":"Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers' carts by knowing the cart tokenValue. An attacker who obtains a cart tokenValue can add arbitrary items to another customer's cart. The endpoint returns the full cart representation in the response (HTTP 201). The issue is fixed in versions: 2.0.16, 2.1.12, 2.2.3 and above.","aliases":["GHSA-wjmg-4cq5-m8hg"],"modified":"2026-08-12T03:51:39.138603193Z","published":"2026-03-10T21:25:20.368Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31821.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31821.json"},{"type":"ADVISORY","url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-wjmg-4cq5-m8hg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31821"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sylius/sylius","events":[{"introduced":"6dd3ca9895be7ab7e6cb71f37af2ef66af17cbe0"},{"fixed":"af579b0b6eaa10ea0883fb458484718c80fc96c7"},{"introduced":"a5a816f9f1fcb5abd2d42b27801656aa2ae9bf0d"},{"fixed":"d8092f21ee9606b0155231fe892d9d54fc44986e"},{"introduced":"7aa47be3a617f75337d73d245352ea700bc8a1ef"},{"fixed":"111d96b1bea7cb59bc2f7b4c6d35d5cd05872195"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.0.16"},{"introduced":"2.1.0"},{"fixed":"2.1.12"},{"introduced":"2.2.0"},{"fixed":"2.2.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*"}}],"versions":["v2.2.2","v2.1.11","v2.2.1","v2.1.10","v2.0.15","v2.2.0","v2.1.9","v2.0.14","v2.1.8","v2.1.7","v2.1.6","v2.1.5","v2.0.13","v2.1.4","v2.0.12","v2.1.3","v2.0.11","v2.1.2","v2.0.10","v2.1.1","v2.0.9","v2.1.0","v2.0.8","v2.0.7","v2.0.6","v2.0.5","v2.0.4","v2.0.3","v2.0.2","v2.0.1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31821.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}