{"id":"GHSA-665x-ppc4-685w","summary":"OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure","details":"# Cross-user wishlist item import via shared wishlist code, leading to private option disclosure and file-disclosure variant\n\n## Summary\n\nThe shared wishlist add-to-cart endpoint authorizes access with a public `sharing_code`, but loads the acted-on wishlist item by a separate global `wishlist_item_id` and never verifies that the item belongs to the shared wishlist referenced by that code.\n\nThis lets an attacker use:\n\n- a valid shared wishlist code for wishlist A\n- a wishlist item ID belonging to victim wishlist B\n\nto import victim item B into the attacker's cart through the shared wishlist flow for wishlist A.\n\nBecause the victim item's stored `buyRequest` is reused during cart import, the victim's private custom-option data is copied into the attacker's quote. If the product uses a file custom option, this can be elevated to cross-user file disclosure because the imported file metadata is preserved and the download endpoint is not ownership-bound.\n\n## Vulnerability Type\n\n- Broken object-level authorization / IDOR\n- Cross-user data disclosure\n- Cross-user file disclosure variant\n\n## Root Cause\n\nIn `app/code/core/Mage/Wishlist/controllers/SharedController.php`, the shared flow does:\n\n```php\n$item = Mage::getModel('wishlist/item')-\u003eload($itemId);\n$wishlist = Mage::getModel('wishlist/wishlist')-\u003eloadByCode($code);\n...\n$item-\u003eaddToCart($cart);\n```\n\nRelevant lines:\n\n- `SharedController.php:86` loads the wishlist item by global ID\n- `SharedController.php:87` loads the wishlist by shared code\n- `SharedController.php:99` imports the item into cart\n\nThere is no check that:\n\n```php\n$item-\u003egetWishlistId() == $wishlist-\u003egetId()\n```\n\nThe safe owner flow in `app/code/core/Mage/Wishlist/controllers/IndexController.php:521-528` does preserve this binding by deriving the wishlist from `item-\u003egetWishlistId()`.\n\nThe imported item keeps its original `buyRequest` because `app/code/core/Mage/Wishlist/Model/Item.php:370-372` passes that stored request directly into:\n\n```php\n$cart-\u003eaddProduct($product, $buyRequest);\n```\n\n## Security Impact\n\n### Baseline impact\n\nAn attacker can import another user's private wishlist item into the attacker's own cart, using an unrelated shared wishlist code.\n\nThis is a clear cross-user authorization bypass. The victim item's private configuration is copied into the attacker's quote, including custom-option values such as personalized text.\n\n### Stronger variant: cross-user file disclosure\n\nIf the victim item contains a custom option of type `file`, the imported quote item preserves file metadata such as:\n\n- `quote_path`\n- `order_path`\n- `secret_key`\n\nThe file option renderer in `app/code/core/Mage/Catalog/Model/Product/Option/Type/File.php:547-552` generates a download URL from:\n\n- the imported `sales/quote_item_option` ID\n- the preserved `secret_key`\n\nThe downloader in `app/code/core/Mage/Sales/controllers/DownloadController.php:150-185`:\n\n- loads quote item option by global ID\n- verifies only product option type and `secret_key`\n- reads the file from `order_path` or `quote_path`\n\nIt does not verify ownership of the quote item, order, or original wishlist item. This creates a cross-user file disclosure path once victim file metadata has been imported.\n\n## Steps To Reproduce\n\n### Lab data\n\n- shared wishlist A:\n  - `wishlist_id = 1`\n  - `customer_id = 2`\n  - `sharing_code = 6376bb8c37a09c2de3664bd8cdc16412`\n- victim wishlist B:\n  - `wishlist_id = 2`\n  - `customer_id = 3`\n- victim item:\n  - `wishlist_item_id = 1`\n  - `wishlist_id = 2`\n  - `product_id = 2`\n- victim private text option marker:\n  - `VICTIM-MARKER-49040822`\n\n### Reproduction\n\nSend:\n\n```http\nGET /wishlist/shared/cart/?code=6376bb8c37a09c2de3664bd8cdc16412&item=1\n```\n\nWhere:\n\n- `code` belongs to shared wishlist A\n- `item=1` belongs to victim wishlist B\n\n### Expected result\n\nThe request should be rejected because the item does not belong to the shared wishlist referenced by the `sharing_code`.\n\n### Actual result\n\nThe application imports victim item `1` into the attacker's quote anyway.\n\n## Verified Evidence\n\n### Baseline variant\n\nPreviously verified at quote/option level in lab:\n\n```text\noption_1 = VICTIM-MARKER-49040822\n```\n\nThis shows that the attacker's cart received victim-private custom-option data from another user's wishlist item.\n\n### File-disclosure variant\n\nPreviously verified in lab after importing a victim file-option payload:\n\n```text\n/sales/download/downloadCustomOption/id/9/key/86fca9b61c0b891b52fb/\n```\n\nThis URL was generated from imported quote item option data containing the victim file metadata and secret key.\n\n## Why This Is A Valid Bug\n\nThis is not a timing issue and does not depend on non-default security settings.\n\nThe bug is a direct authorization failure:\n\n- authorization is based on wishlist A's share code\n- the acted-on object is item B from another wishlist\n- there is no item-to-wishlist binding check\n- victim-controlled item state is then copied into attacker-controlled cart state\n\nThat is a broken object-level authorization issue with clear cross-user impact.\n\n## Remediation\n\nIn `SharedController::cartAction()`, reject any request where the loaded item does not belong to the wishlist loaded from the share code:\n\n```php\n$item = Mage::getModel('wishlist/item')-\u003eload($itemId);\n$wishlist = Mage::getModel('wishlist/wishlist')-\u003eloadByCode($code);\n\nif (!$item-\u003egetId() || !$wishlist-\u003egetId() || (int) $item-\u003egetWishlistId() !== (int) $wishlist-\u003egetId()) {\n    return $this-\u003e_forward('noRoute');\n}\n```\n\nDefense in depth:\n\n- bind `sales/download/downloadCustomOption` to the current quote/order owner instead of trusting only `id + secret_key`","aliases":["CVE-2026-40098"],"modified":"2026-05-05T16:02:13.929148Z","published":"2026-04-21T15:20:41Z","database_specific":{"nvd_published_at":"2026-04-20T17:16:34Z","cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-21T15:20:41Z"},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-665x-ppc4-685w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40098"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/pull/5446"},{"type":"PACKAGE","url":"https://github.com/OpenMage/magento-lts"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.17.0"}],"affected":[{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.17.0"}]}],"versions":["1.9.1.1","1.9.2.0","1.9.2.1","1.9.2.2","1.9.2.3","1.9.2.4","1.9.3.0","1.9.3.1","v19.4.0","v19.4.1","v19.4.10","v19.4.11","v19.4.12","v19.4.13","v19.4.14","v19.4.15","v19.4.16","v19.4.17","v19.4.18","v19.4.19","v19.4.2","v19.4.20","v19.4.21","v19.4.22","v19.4.23","v19.4.3","v19.4.4","v19.4.5","v19.4.6","v19.4.7","v19.4.8","v19.4.9","v19.5.0","v19.5.0-rc1","v19.5.0-rc2","v19.5.0-rc3","v19.5.0-rc4","v19.5.0-rc5","v19.5.1","v19.5.2","v19.5.3","v20.0.0","v20.0.1","v20.0.10","v20.0.11","v20.0.12","v20.0.13","v20.0.14","v20.0.15","v20.0.16","v20.0.17","v20.0.18","v20.0.19","v20.0.2","v20.0.20","v20.0.3","v20.0.4","v20.0.5","v20.0.6","v20.0.7","v20.0.8","v20.1.0","v20.1.0-rc1","v20.1.0-rc2","v20.1.0-rc3","v20.1.0-rc4","v20.1.0-rc5","v20.1.0-rc6","v20.1.0-rc7","v20.1.1","v20.10.0","v20.10.1","v20.10.2","v20.11.0","v20.12.0","v20.12.1","v20.12.2","v20.12.3","v20.13.0","v20.14.0","v20.15.0","v20.16.0","v20.2.0","v20.3.0","v20.4.0","v20.5.0","v20.6.0","v20.7.0","v20.8.0","v20.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-665x-ppc4-685w/GHSA-665x-ppc4-685w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}