Skip to content

StyleSmuggler mitigation: Magento DI code scanners are CLI-only (+ vaimo/composer-patches) - #1

Merged
paales merged 2 commits into
mainfrom
stylesmuggler-di-scanner-guard
Sep 7, 2026
Merged

paales merged 2 commits into
mainfrom
stylesmuggler-di-scanner-guard

Conversation

@paales

@paales paales commented Sep 5, 2026

Copy link
Copy Markdown
Member

Why

Sansec: StyleSmuggler (2026-09-05) — unauthenticated RCE in every Magento Open Source / Adobe Commerce / Mage-OS release up to 2.4.9, exploited in the wild since 2026-09-04, no vendor fix (Adobe's next bulletin is 2026-09-08). Attacker-controlled text reaches the email template filter; its {{block}} directive drives a method chain into the DI compiler's code scanners, whose include/require then executes a poisoned var/report or var/log file (mechanism).

What

  • patches/stylesmuggler-di-scanner-guard.patch — the disrex-group mitigation, targeted at mage-os/magento2-base: ArrayScanner, ClassesScanner and XmlInterceptorScanner throw on any non-CLI SAPI (they only run from setup:di:compile). Dry-run verified against Mage-OS 3.4 files.
  • The template had no patch mechanism, so this introduces the org standard: vaimo/composer-patches ^6.0 (require + allow-plugins), extra.patches-search: patches. composer.lock updated for that package only (composer update vaimo/composer-patches --no-install: adds vaimo/composer-patches, vaimo/topological-sort, loophp/phposinfo — nothing else moves). Every project scaffolded from this template inherits both.

⚠️ Depends on the build recipe

Built by the deployyy mageos-3 recipe, which today copies only composer.json/composer.lock before composer install — patches/ is not in the context at install time, so the plugin silently applies nothing. Companion PR ho-nl/deployyy ("recipe copies the project's patches/ before composer install") fixes that; merge it first. Until then this PR is inert, never harmful.

Remove the patch once the vendor fix is in. Same change in ho-nl/project-mageos-demo.

🤖 Generated with Claude Code

https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2


Generated by Claude Code

Sansec disclosed StyleSmuggler on 2026-09-05: an unauthenticated RCE in every
Magento Open Source / Adobe Commerce / Mage-OS release up to 2.4.9, exploited in
the wild since 2026-09-04, with no vendor fix (Adobe's next bulletin is
2026-09-08). Attacker-controlled text reaches the email template filter; its
{{block}} directive drives a method chain into the DI compiler's code scanners,
whose include/require then executes a poisoned var/report or var/log file.

Those scanners (ArrayScanner, ClassesScanner, XmlInterceptorScanner) only ever
run from bin/magento setup:di:compile. This adds the disrex-group mitigation
(https://github.com/disrex-group/stylesmuggler-mitigation) as a
vaimo/composer-patches patch targeted at mage-os/magento2-base: each scanner
throws on any non-CLI SAPI, which closes the sink without touching the email
path (guarding the entry point would break order-confirmation mails).

The template had no patch mechanism yet, so this also introduces the org
standard: vaimo/composer-patches (allow-plugins + require, lock updated for
that package only) with `extra.patches-search: patches` — every project
scaffolded from this template inherits both the mechanism and the guard.

Built by the deployyy mageos-3 recipe, which today copies only
composer.json/lock before `composer install`; the patch takes effect once
ho-nl/deployyy ships the recipe change that copies patches/ at install time
(companion PR). Until then it is inert, never harmful.

Remove the patch once the vendor fix is in.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2
@private-packagist

Copy link
Copy Markdown

composer.lock

Package changes

Package Operation From To About
loophp/phposinfo add - 1.8.0 view code - License: MIT License
vaimo/composer-patches add - 6.0.2 view code - License: MIT License
vaimo/topological-sort add - 2.0.1 view code - License: MIT License

Settings · Docs · Powered by Private Packagist

The mageos-3 recipe now copies the project's patches/ directory into the
build context BEFORE composer install (ho-nl/deployyy#5), so a patch here
is applied by vaimo/composer-patches during the install. Say so next to the
other committed-on-purpose files, with the one rule that matters: a patch
the plugin cannot apply fails the build, but a patch it never sees (wrong
directory, wrong package target) is a silent no-op — verify in the image.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2
@paales
paales merged commit c0f06a6 into main Sep 7, 2026
1 check passed
@paales
paales deleted the stylesmuggler-di-scanner-guard branch September 7, 2026 13:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants