{"id":"GHSA-595p-g7xc-c333","summary":"Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling","details":"### Impact\n\nVersions of the Algolia Search & Discovery extension for Magento 2 prior to **3.17.2** and **3.16.2** contain a vulnerability where data read from the database was treated as a trusted source during job execution.\n\nIf an attacker is able to modify records used by the extension’s indexing queue, this could result in **arbitrary PHP code execution** when the affected job is processed.\n\nExploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled.\n\n---\n\n### Patches\n\nThis vulnerability has been fixed in the following versions:\n\n- **3.17.2**\n- **3.16.2**\n\nMerchants should upgrade to a supported patched version immediately.\n\nVersions outside the supported maintenance window do **not** receive security updates and remain vulnerable.\n\n---\n\n### Workarounds\n\nUpgrading to a patched version is the only recommended remediation.\n\nIf an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:\n\n- Disable the Algolia indexing queue to prevent queued jobs from being executed.\n- Restrict job execution logic to an explicit allowlist of permitted operations.\n- Review the contents of the `algoliasearch_queue` table for unexpected or unrecognized entries.\n- If queue archiving is enabled, review historical records in `algoliasearch_queue_archive`.\n\nThese mitigations are provided as guidance only and do not replace upgrading to a patched version.\n\n---\n\n### References\n\n- Algolia Search & Discovery for Magento 2 releases:\n  - [3.16.2](https://github.com/algolia/algoliasearch-magento-2/releases/tag/3.16.2)\n  - [3.17.2](https://github.com/algolia/algoliasearch-magento-2/releases/tag/3.17.2)","modified":"2026-02-03T02:56:34.571673Z","published":"2026-01-14T21:46:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-01-14T21:46:11Z","nvd_published_at":null,"cwe_ids":["CWE-74"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/algolia/algoliasearch-magento-2/security/advisories/GHSA-595p-g7xc-c333"},{"type":"PACKAGE","url":"https://github.com/algolia/algoliasearch-magento-2"},{"type":"WEB","url":"https://github.com/algolia/algoliasearch-magento-2/releases/tag/3.16.2"},{"type":"WEB","url":"https://github.com/algolia/algoliasearch-magento-2/releases/tag/3.17.2"}],"affected":[{"package":{"name":"algolia/algoliasearch-magento-2","ecosystem":"Packagist","purl":"pkg:composer/algolia/algoliasearch-magento-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.17.0-beta.1"},{"fixed":"3.17.2"}]}],"versions":["3.17.0","3.17.0-beta.1","3.17.0-beta.2","3.17.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.17.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-595p-g7xc-c333/GHSA-595p-g7xc-c333.json"}},{"package":{"name":"algolia/algoliasearch-magento-2","ecosystem":"Packagist","purl":"pkg:composer/algolia/algoliasearch-magento-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.16.2"}]}],"versions":["0.8.2","0.8.3","0.8.4","0.9.0","0.9.1","1.0.0","1.0.1","1.0.10","1.0.3","1.0.4","1.0.5","1.0.6","1.0.8","1.0.9","1.1.0","1.10.0","1.11.0","1.11.1","1.11.2","1.11.3","1.12.0","1.12.1","1.13.0","1.13.1","1.13.2","1.13.3","1.2.0","1.2.1","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.7.1","1.7.2","1.8.0","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.9.0","1.9.1","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","3.0.0","3.0.1","3.0.2","3.1.0","3.10.0","3.10.1","3.10.2","3.10.3","3.10.4","3.10.5","3.10.6","3.11.0","3.11.0-beta","3.11.1-beta","3.12.0","3.12.1","3.13.0","3.13.1","3.13.2","3.13.3","3.13.4","3.13.5","3.13.6","3.13.7","3.13.8","3.14.0","3.14.0-beta.1","3.14.0-beta.2","3.14.1","3.14.2","3.14.3","3.14.4","3.14.5","3.15.0","3.15.0-beta.1","3.15.0-beta.2","3.15.1","3.15.2","3.15.3","3.16.0","3.16.0-beta.1","3.16.0-beta.2","3.16.1","3.2.0","3.3.0","3.3.1","3.4.0","3.6.0","3.6.1","3.7.0","3.7.0-p1","3.7.0-p2","3.8.0","3.8.1","3.9.0","3.9.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.16.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-595p-g7xc-c333/GHSA-595p-g7xc-c333.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}