{"id":"GHSA-6vqf-6fhm-7rc6","summary":"OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module","details":"The Dataflow module in OpenMage LTS uses a weak blacklist filter (`str_replace('../', '', $input)`) to prevent path traversal attacks. This filter can be bypassed using patterns like `..././` or `....//`, which after the replacement still result in `../`. An authenticated administrator can exploit this to read arbitrary files from the server filesystem.\n\n\n| Metric                   | Value     | Justification                         |\n| ------------------------ | --------- | ------------------------------------- |\n| Attack Vector (AV)       | Network   | Exploitable via admin panel           |\n| Attack Complexity (AC)   | Low       | Simple bypass pattern                 |\n| Privileges Required (PR) | High      | Requires admin authentication         |\n| User Interaction (UI)    | None      | No additional user interaction needed |\n| Scope (S)                | Unchanged | Impacts the vulnerable component      |\n| Confidentiality (C)      | High      | Can read sensitive system files       |\n| Integrity (I)            | None      | Read-only vulnerability               |\n| Availability (A)         | None      | No impact on availability             |\n\n## Affected Products\n\n- OpenMage LTS versions \u003c 20.16.1\n- All versions derived from Magento 1.x with these code paths\n\n## Affected Files\n\n| File                                                         | Line | Vulnerable Code                          |\n| ------------------------------------------------------------ | ---- | ---------------------------------------- |\n| `app/code/core/Mage/Dataflow/Model/Convert/Parser/Csv.php`   | 67   | `str_replace('../', '', urldecode(...))` |\n| `app/code/core/Mage/Dataflow/Model/Convert/Parser/Xml/Excel.php` | 63   | `str_replace('../', '', urldecode(...))` |\n\n## Vulnerability Details\n\nThe Dataflow module allows administrators to import data from files. The `files` parameter specifies which file to import from the `var/import/` directory. To prevent path traversal, the code uses `str_replace()` to remove `../` sequences:\n\n```php\n$file = Mage::app()-\u003egetConfig()-\u003egetTempVarDir() . '/import/'\n    . str_replace('../', '', urldecode(Mage::app()-\u003egetRequest()-\u003egetParam('files')));\n```\n\nHowever, `str_replace()` only performs a single pass, making it trivially bypassable:\n\n### Bypass Examples\n\n| Input                          | After `str_replace('../', '', ...)` | Result    |\n| ------------------------------ | ----------------------------------- | --------- |\n| `..././`                       | `../`                               | Bypass    |\n| `....//`                       | `../`                               | Bypass    |\n| `..././..././..././etc/passwd` | `../../../etc/passwd`               | File read |\n\n### Attack Scenario\n\n1. Attacker gains admin access (via compromised credentials, social engineering, etc.)\n2. Navigate to System \u003e Import/Export \u003e Dataflow Profiles\n3. Create or modify an import profile\n4. Set the `files` parameter to: `..././..././..././etc/passwd`\n5. Run the profile to read the contents of `/etc/passwd`\n\n### Proof of Concept\n\n```\n# Request to Dataflow with bypass pattern\nGET /admin/system_convert_gui/run/id/1/?files=..././..././..././etc/passwd\n\n# The str_replace removes '../' leaving:\n# ..././..././..././etc/passwd -\u003e ../../../etc/passwd\n\n# Final path resolves to:\n# /var/www/html/var/import/../../../etc/passwd -\u003e /etc/passwd\n```\n\n## Remediation\n\nReplace the weak `str_replace()` filter with `basename()` to extract only the filename:\n\n```php\n// Before (vulnerable)\n$file = Mage::app()-\u003egetConfig()-\u003egetTempVarDir() . '/import/'\n    . str_replace('../', '', urldecode(Mage::app()-\u003egetRequest()-\u003egetParam('files')));\n\n// After (fixed)\n$file = Mage::app()-\u003egetConfig()-\u003egetTempVarDir() . '/import/'\n    . basename(urldecode(Mage::app()-\u003egetRequest()-\u003egetParam('files')));\n```\n\nUsing `basename()` ensures only the filename portion is used, completely preventing any path traversal regardless of the input pattern.\n\n## Workarounds\n\nIf immediate upgrade is not possible:\n\n1. **Restrict admin access**: Limit Dataflow access to trusted administrators only\n2. **Disable Dataflow**: If not in use, disable the Dataflow module entirely\n3. **Web Application Firewall**: Block requests containing path traversal patterns\n4. **File permissions**: Ensure the web server user has minimal filesystem permissions\n5. **Monitor admin activity**: Alert on suspicious Dataflow profile execution\n\n## Impact\n\nAn attacker with admin access can read sensitive files including:\n\n- `/etc/passwd` - System user information\n- `app/etc/local.xml` - Database credentials\n- `.env` files - Environment secrets\n- Log files - Potentially sensitive application data\n- Configuration files - Server and application configuration\n\n## Credit\n\nThis vulnerability was discovered and responsibly disclosed by [blackhat2013](https://hackerone.com/blackhat2013) through HackerOne.\n\n## Timeline\n\n- **2025-12-31**: Vulnerability reported via HackerOne\n- **2026-01-21**: Fix developed and tested","aliases":["CVE-2026-25525"],"modified":"2026-04-21T14:56:36.782121Z","published":"2026-04-21T14:35:02Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-21T14:35:02Z","nvd_published_at":"2026-04-20T17:16:32Z","cwe_ids":["CWE-184","CWE-22"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-6vqf-6fhm-7rc6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25525"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/pull/5445"},{"type":"WEB","url":"https://hackerone.com/reports/3482926"},{"type":"PACKAGE","url":"https://github.com/OpenMage/magento-lts"},{"type":"WEB","url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.17.0"}],"affected":[{"package":{"name":"openmage/magento-lts","ecosystem":"Packagist","purl":"pkg:composer/openmage/magento-lts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.17.0"}]}],"versions":["1.9.1.1","1.9.2.0","1.9.2.1","1.9.2.2","1.9.2.3","1.9.2.4","1.9.3.0","1.9.3.1","v19.4.0","v19.4.1","v19.4.10","v19.4.11","v19.4.12","v19.4.13","v19.4.14","v19.4.15","v19.4.16","v19.4.17","v19.4.18","v19.4.19","v19.4.2","v19.4.20","v19.4.21","v19.4.22","v19.4.23","v19.4.3","v19.4.4","v19.4.5","v19.4.6","v19.4.7","v19.4.8","v19.4.9","v19.5.0","v19.5.0-rc1","v19.5.0-rc2","v19.5.0-rc3","v19.5.0-rc4","v19.5.0-rc5","v19.5.1","v19.5.2","v19.5.3","v20.0.0","v20.0.1","v20.0.10","v20.0.11","v20.0.12","v20.0.13","v20.0.14","v20.0.15","v20.0.16","v20.0.17","v20.0.18","v20.0.19","v20.0.2","v20.0.20","v20.0.3","v20.0.4","v20.0.5","v20.0.6","v20.0.7","v20.0.8","v20.1.0","v20.1.0-rc1","v20.1.0-rc2","v20.1.0-rc3","v20.1.0-rc4","v20.1.0-rc5","v20.1.0-rc6","v20.1.0-rc7","v20.1.1","v20.10.0","v20.10.1","v20.10.2","v20.11.0","v20.12.0","v20.12.1","v20.12.2","v20.12.3","v20.13.0","v20.14.0","v20.15.0","v20.16.0","v20.2.0","v20.3.0","v20.4.0","v20.5.0","v20.6.0","v20.7.0","v20.8.0","v20.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-6vqf-6fhm-7rc6/GHSA-6vqf-6fhm-7rc6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}