{"id":"GHSA-mr9r-h354-966r","summary":"Sylius: IDOR on Shop Payment Request API endpoints","details":"### Impact\nThe `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order.\n\nAn attacker who obtains a payment request hash can:\n\n- read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals);\n- update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer.\n\nThe hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token.\n\nThe creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order.\n\n### Patches\nThe issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6.\n\n### Workarounds\nUntil you can upgrade, apply the following workaround. It enforces ownership on the existing endpoints, so that:\n\n- an authenticated shop user may only access payment requests of their own orders;\n- an anonymous caller may only access payment requests of guest orders (the order's customer has no associated user account);\n- everyone else receives `404 Not Found`.\n\n#### Step 1. Add a query extension that filters the `GET` operation\n\nCreate file `src/ApiPlatform/QueryExtension/PaymentRequestOwnershipExtension.php`:\n\n```php\n\u003c?php\n\ndeclare(strict_types=1);\n\nnamespace App\\ApiPlatform\\QueryExtension;\n\nuse ApiPlatform\\Doctrine\\Orm\\Extension\\QueryItemExtensionInterface;\nuse ApiPlatform\\Doctrine\\Orm\\Util\\QueryNameGeneratorInterface;\nuse ApiPlatform\\Metadata\\Operation;\nuse Doctrine\\ORM\\QueryBuilder;\nuse Sylius\\Bundle\\ApiBundle\\Context\\UserContextInterface;\nuse Sylius\\Bundle\\ApiBundle\\SectionResolver\\ShopApiSection;\nuse Sylius\\Bundle\\CoreBundle\\SectionResolver\\SectionProviderInterface;\nuse Sylius\\Component\\Core\\Model\\ShopUserInterface;\nuse Sylius\\Component\\Payment\\Model\\PaymentRequestInterface;\n\nfinal readonly class PaymentRequestOwnershipExtension implements QueryItemExtensionInterface\n{\n    public function __construct(\n        private SectionProviderInterface $sectionProvider,\n        private UserContextInterface $userContext,\n    ) {\n    }\n\n    public function applyToItem(\n        QueryBuilder $queryBuilder,\n        QueryNameGeneratorInterface $queryNameGenerator,\n        string $resourceClass,\n        array $identifiers,\n        ?Operation $operation = null,\n        array $context = [],\n    ): void {\n        if (!is_a($resourceClass, PaymentRequestInterface::class, true)) {\n            return;\n        }\n\n        if (!$this-\u003esectionProvider-\u003egetSection() instanceof ShopApiSection) {\n            return;\n        }\n\n        $rootAlias = $queryBuilder-\u003egetRootAliases()[0];\n        $paymentJoin = $queryNameGenerator-\u003egenerateJoinAlias('payment');\n        $orderJoin = $queryNameGenerator-\u003egenerateJoinAlias('order');\n        $customerJoin = $queryNameGenerator-\u003egenerateJoinAlias('customer');\n        $userJoin = $queryNameGenerator-\u003egenerateJoinAlias('user');\n        $createdByGuestParameterName = $queryNameGenerator-\u003egenerateParameterName('createdByGuest');\n\n        $queryBuilder\n            -\u003einnerJoin(sprintf('%s.payment', $rootAlias), $paymentJoin)\n            -\u003einnerJoin(sprintf('%s.order', $paymentJoin), $orderJoin)\n            -\u003eleftJoin(sprintf('%s.customer', $orderJoin), $customerJoin)\n            -\u003eleftJoin(sprintf('%s.user', $customerJoin), $userJoin)\n        ;\n\n        $user = $this-\u003euserContext-\u003egetUser();\n\n        if ($user instanceof ShopUserInterface) {\n            $customerParam = $queryNameGenerator-\u003egenerateParameterName('customer');\n\n            $queryBuilder\n                -\u003eandWhere($queryBuilder-\u003eexpr()-\u003eeq(sprintf('%s.customer', $orderJoin), sprintf(':%s', $customerParam)))\n                -\u003esetParameter($customerParam, $user-\u003egetCustomer())\n            ;\n\n            return;\n        }\n\n        $queryBuilder\n            -\u003eandWhere(\n                $queryBuilder-\u003eexpr()-\u003eorX(\n                    $queryBuilder-\u003eexpr()-\u003eisNull($userJoin),\n                    $queryBuilder-\u003eexpr()-\u003eisNull(sprintf('%s.customer', $orderJoin)),\n                    $queryBuilder-\u003eexpr()-\u003eandX(\n                        $queryBuilder-\u003eexpr()-\u003eisNotNull($userJoin),\n                        $queryBuilder-\u003eexpr()-\u003eeq(sprintf('%s.createdByGuest', $orderJoin), sprintf(':%s', $createdByGuestParameterName)),\n                    ),\n                ),\n            )\n            -\u003esetParameter($createdByGuestParameterName, true)\n        ;\n    }\n}\n```\n\n#### Step 2. Decorate the `PUT` state provider\n\nCreate file `src/ApiPlatform/StateProvider/PaymentRequestOwnershipProvider.php`:\n\n```php\n\u003c?php\n\ndeclare(strict_types=1);\n\nnamespace App\\ApiPlatform\\StateProvider;\n\nuse ApiPlatform\\Metadata\\Operation;\nuse ApiPlatform\\State\\ProviderInterface;\nuse Sylius\\Bundle\\ApiBundle\\Context\\UserContextInterface;\nuse Sylius\\Component\\Core\\Model\\CustomerInterface;\nuse Sylius\\Component\\Core\\Model\\OrderInterface;\nuse Sylius\\Component\\Core\\Model\\PaymentInterface;\nuse Sylius\\Component\\Core\\Model\\ShopUserInterface;\nuse Sylius\\Component\\Payment\\Model\\PaymentRequestInterface;\n\n/** @implements ProviderInterface\u003cPaymentRequestInterface\u003e */\nfinal readonly class PaymentRequestOwnershipProvider implements ProviderInterface\n{\n    /** @param ProviderInterface\u003cPaymentRequestInterface\u003e $inner */\n    public function __construct(\n        private ProviderInterface $inner,\n        private UserContextInterface $userContext,\n    ) {\n    }\n\n    public function provide(Operation $operation, array $uriVariables = [], array $context = []): array|object|null\n    {\n        $paymentRequest = $this-\u003einner-\u003eprovide($operation, $uriVariables, $context);\n        if (!$paymentRequest instanceof PaymentRequestInterface) {\n            return $paymentRequest;\n        }\n\n        if (!$this-\u003eisAccessible($paymentRequest)) {\n            return null;\n        }\n\n        return $paymentRequest;\n    }\n\n    private function isAccessible(PaymentRequestInterface $paymentRequest): bool\n    {\n        $payment = $paymentRequest-\u003egetPayment();\n        if (!$payment instanceof PaymentInterface) {\n            return false;\n        }\n\n        $order = $payment-\u003egetOrder();\n        if (!$order instanceof OrderInterface) {\n            return false;\n        }\n\n        $user = $this-\u003euserContext-\u003egetUser();\n\n        if ($user instanceof ShopUserInterface) {\n            $customer = $user-\u003egetCustomer();\n\n            return $customer instanceof CustomerInterface && $order-\u003egetCustomer() === $customer;\n        }\n\n        $customer = $order-\u003egetCustomer();\n\n        return null === $customer\n               || null === $customer-\u003egetUser()\n               || $order-\u003eisCreatedByGuest();\n    }\n}\n```\n\n#### Step 3. Guard the `POST` creation endpoint with a command-bus middleware\n\nThe `POST /api/v2/shop/orders/{tokenValue}/payment-requests` operation is a `messenger: input` operation: it dispatches a `Sylius\\Bundle\\ApiBundle\\Command\\Payment\\AddPaymentRequest` command whose `orderTokenValue` comes straight from the URL, so no query extension or state provider runs. Add a middleware on the Sylius command bus that loads the order, applies the same ownership rule, and aborts with `404` before the handler runs.\n\nCreate file `src/Messenger/Middleware/PaymentRequestOwnershipMiddleware.php`:\n\n```php\n\u003c?php\n\ndeclare(strict_types=1);\n\nnamespace App\\Messenger\\Middleware;\n\nuse Sylius\\Bundle\\ApiBundle\\Command\\Payment\\AddPaymentRequest;\nuse Sylius\\Bundle\\ApiBundle\\Context\\UserContextInterface;\nuse Sylius\\Component\\Core\\Model\\CustomerInterface;\nuse Sylius\\Component\\Core\\Model\\OrderInterface;\nuse Sylius\\Component\\Core\\Model\\ShopUserInterface;\nuse Sylius\\Component\\Core\\Repository\\OrderRepositoryInterface;\nuse Symfony\\Component\\HttpKernel\\Exception\\NotFoundHttpException;\nuse Symfony\\Component\\Messenger\\Envelope;\nuse Symfony\\Component\\Messenger\\Middleware\\MiddlewareInterface;\nuse Symfony\\Component\\Messenger\\Middleware\\StackInterface;\n\nfinal readonly class PaymentRequestOwnershipMiddleware implements MiddlewareInterface\n{\n    /** @param OrderRepositoryInterface\u003cOrderInterface\u003e $orderRepository */\n    public function __construct(\n        private OrderRepositoryInterface $orderRepository,\n        private UserContextInterface $userContext,\n    ) {\n    }\n\n    public function handle(Envelope $envelope, StackInterface $stack): Envelope\n    {\n        $command = $envelope-\u003egetMessage();\n\n        if ($command instanceof AddPaymentRequest && !$this-\u003eisOrderAccessible($command-\u003eorderTokenValue)) {\n            throw new NotFoundHttpException('Not Found');\n        }\n\n        return $stack-\u003enext()-\u003ehandle($envelope, $stack);\n    }\n\n    private function isOrderAccessible(string $orderTokenValue): bool\n    {\n        /** @var OrderInterface|null $order */\n        $order = $this-\u003eorderRepository-\u003efindOneByTokenValue($orderTokenValue);\n        if (null === $order) {\n            // Unknown token — let the handler return its own 404 (PaymentNotFoundException).\n            return true;\n        }\n\n        $user = $this-\u003euserContext-\u003egetUser();\n\n        if ($user instanceof ShopUserInterface) {\n            $customer = $user-\u003egetCustomer();\n\n            return $customer instanceof CustomerInterface && $order-\u003egetCustomer() === $customer;\n        }\n\n        $customer = $order-\u003egetCustomer();\n\n        return null === $customer\n            || null === $customer-\u003egetUser()\n            || $order-\u003eisCreatedByGuest();\n    }\n}\n```\n\n#### Step 4. Wire the services\n\nAppend to `config/services.yaml`:\n\n```yaml\nservices:\n    App\\ApiPlatform\\QueryExtension\\PaymentRequestOwnershipExtension:\n        arguments:\n            - '@sylius.section_resolver.uri_based'\n            - '@sylius_api.context.user.token_based'\n        tags:\n            - { name: api_platform.doctrine.orm.query_extension.item }\n\n    App\\ApiPlatform\\StateProvider\\PaymentRequestOwnershipProvider:\n        decorates: sylius_api.state_provider.shop.payment.payment_request.item\n        arguments:\n            $inner: '@.inner'\n            $userContext: '@sylius_api.context.user.token_based'\n\n    App\\Messenger\\Middleware\\PaymentRequestOwnershipMiddleware:\n        arguments:\n            - '@sylius.repository.order'\n            - '@sylius_api.context.user.token_based'\n```\n\nWith the default Sylius-Standard `services.yaml` (`autowire: true`, `autoconfigure: true`) the two classes are already autoloaded, the block above only adds the tag and the decoration, which cannot be derived from the constructor signatures.\n\n#### Step 5. Register the middleware on the Sylius command bus\n\nAdd to `config/packages/messenger.yaml`:\n\n```yaml\nframework:\n    messenger:\n        buses:\n            sylius.command_bus:\n                middleware:\n                    - 'App\\Messenger\\Middleware\\PaymentRequestOwnershipMiddleware'\n                    - 'validation'\n                    - 'doctrine_transaction'\n```\n\n#### Step 6. Clear the cache\n\n```bash\nbin/console cache:clear\n```\n\n### Reporters\n\nWe would like to extend our gratitude to the following individuals for their detailed reporting and responsible disclosure of this vulnerability:\n- Fase Rais Baradika (@baradika)\n- Anshu Chimala (@achimala)\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [Sylius issues](https://github.com/Sylius/Sylius/issues?q=sort%3Aupdated-desc+is%3Aissue+is%3Aopen)\n- Email us at [security@sylius.com](mailto:security@sylius.com)","aliases":["CVE-2026-53639"],"modified":"2026-07-09T21:26:42.075726Z","published":"2026-07-09T21:03:51Z","database_specific":{"cwe_ids":["CWE-639"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-09T21:03:51Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-mr9r-h354-966r"},{"type":"PACKAGE","url":"https://github.com/Sylius/Sylius"}],"affected":[{"package":{"name":"sylius/sylius","ecosystem":"Packagist","purl":"pkg:composer/sylius/sylius"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.18"}]}],"versions":["v2.0.0","v2.0.1","v2.0.10","v2.0.11","v2.0.12","v2.0.13","v2.0.14","v2.0.15","v2.0.16","v2.0.17","v2.0.2","v2.0.3","v2.0.4","v2.0.5","v2.0.6","v2.0.7","v2.0.8","v2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mr9r-h354-966r/GHSA-mr9r-h354-966r.json"}},{"package":{"name":"sylius/sylius","ecosystem":"Packagist","purl":"pkg:composer/sylius/sylius"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.15"}]}],"versions":["v2.1.0","v2.1.1","v2.1.10","v2.1.11","v2.1.12","v2.1.13","v2.1.14","v2.1.2","v2.1.3","v2.1.4","v2.1.5","v2.1.6","v2.1.7","v2.1.8","v2.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mr9r-h354-966r/GHSA-mr9r-h354-966r.json"}},{"package":{"name":"sylius/sylius","ecosystem":"Packagist","purl":"pkg:composer/sylius/sylius"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.6"}]}],"versions":["v2.2.0","v2.2.1","v2.2.2","v2.2.3","v2.2.4","v2.2.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mr9r-h354-966r/GHSA-mr9r-h354-966r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}