{"id":"DRUPAL-CONTRIB-2026-179","details":"This module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.\n\nThe module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.","aliases":["CVE-2026-96378"],"modified":"2026-09-23T19:15:05.728542832Z","published":"2026-09-23T17:06:19Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-179"}],"affected":[{"package":{"name":"drupal/commerce_decoupled_checkout","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/commerce_decoupled_checkout?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.8.0"}],"database_specific":{"constraint":"\u003e=1.0.0 \u003c1.8.0"}}],"database_specific":{"affected_versions":"\u003e=1.0.0 \u003c1.8.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_decoupled_checkout/DRUPAL-CONTRIB-2026-179.json"}}],"schema_version":"1.9.0","credits":[{"name":"Marcus Johansson (marcus_johansson)","contact":["https://www.drupal.org/u/marcus_johansson"]}]}