{"id":"GHSA-m5f5-28qr-9g9r","summary":"prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE","details":"### Impact\n\nA PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`.\n\nThe module rebuilds the selected search filters from the request URL. The value of a slider filter (**price** or **weight**) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native `unserialize()`.\nBy crafting that value, an attacker can smuggle a malicious serialized PHP object into the cache. When it is deserialized, a gadget chain writes an arbitrary PHP file inside the module directory, which is then used as a webshell to run commands on the server.\n\n### Who is impacted\n\nAny shop using a vulnerable version of `ps_facetedsearch` that displays a filter template containing a slider filter (price or weight). Exploitation is remote and **unauthenticated**, a single crafted front-office request is enough, and leads to remote code\nexecution and full compromise of the shop and its server.\n\n**Affected versions:** `3.0.0` through `4.0.3` (all versions since 3.0.0, including the latest release).\n\n\n### Patches\n\nUpgrade the `ps_facetedsearch` module to the patched version. Upgrading the module is the best action that removes the vulnerability.\n\nOtherwise, you can apply the fix manually in the file `src/Filters/Block.php`:\n\nIn the `getFromCache()` method, replace the native `unserialize()` call:\n\n```php\n// Before\nif (!empty($row)) {\n    return unserialize(current($row));\n}\n\n// After\nif (!empty($row)) {\n    return \\Tools::unSerialize(current($row));\n}\n```\n\n### Until the module is upgraded:\n\n- Remove price and weight slider filters from the filter templates that are exposed on the\n  front office.\n- Clear the faceted-search filter cache, and audit the `modules/ps_facetedsearch/` directory for\n  unexpected PHP files.\n- Monitor search requests for PHP serialization patterns (`O:`, `;i:`, references to classes such\n  as `Monolog\\…`) and block them at the WAF level.\n\n### Resources\n\n- Thank you to Frédéric Moreau (Antadis) and Gilles Caudal (Datalinx) for reporting this vulnerability.","aliases":["CVE-2026-54159"],"modified":"2026-07-10T20:56:35.754523Z","published":"2026-07-10T20:36:56Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-74"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-10T20:36:56Z"},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-m5f5-28qr-9g9r"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/ps_facetedsearch"}],"affected":[{"package":{"name":"prestashop/ps_facetedsearch","ecosystem":"Packagist","purl":"pkg:composer/prestashop/ps_facetedsearch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"4.0.4"}]}],"versions":["v3.0.0","v3.0.1","v3.0.2","v3.0.3","v3.0.4","v3.0.5","v3.0.6","v3.0.7","v3.1.0","v3.10.0","v3.11.0","v3.11.1","v3.12.0","v3.12.1","v3.13.0","v3.13.1","v3.13.2","v3.14.0","v3.14.1","v3.15.0","v3.15.1","v3.16.0","v3.16.1","v3.2.0","v3.2.1","v3.3.0","v3.4.0","v3.4.1","v3.5.0","v3.6.0","v3.7.0","v3.7.1","v3.8.0","v3.9.0","v4.0.0","v4.0.1","v4.0.2","v4.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m5f5-28qr-9g9r/GHSA-m5f5-28qr-9g9r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}