StyleSmuggler mitigation: Magento DI code scanners are CLI-only (+ vaimo/composer-patches) - #1
Merged
Merged
Conversation
Sansec disclosed StyleSmuggler on 2026-09-05: an unauthenticated RCE in every
Magento Open Source / Adobe Commerce / Mage-OS release up to 2.4.9, exploited in
the wild since 2026-09-04, with no vendor fix (Adobe's next bulletin is
2026-09-08). Attacker-controlled text reaches the email template filter; its
{{block}} directive drives a method chain into the DI compiler's code scanners,
whose include/require then executes a poisoned var/report or var/log file.
Those scanners (ArrayScanner, ClassesScanner, XmlInterceptorScanner) only ever
run from bin/magento setup:di:compile. This adds the disrex-group mitigation
(https://github.com/disrex-group/stylesmuggler-mitigation) as a
vaimo/composer-patches patch targeted at mage-os/magento2-base: each scanner
throws on any non-CLI SAPI, which closes the sink without touching the email
path (guarding the entry point would break order-confirmation mails).
The template had no patch mechanism yet, so this also introduces the org
standard: vaimo/composer-patches (allow-plugins + require, lock updated for
that package only) with `extra.patches-search: patches` — every project
scaffolded from this template inherits both the mechanism and the guard.
Built by the deployyy mageos-3 recipe, which today copies only
composer.json/lock before `composer install`; the patch takes effect once
ho-nl/deployyy ships the recipe change that copies patches/ at install time
(companion PR). Until then it is inert, never harmful.
Remove the patch once the vendor fix is in.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2
composer.lockPackage changes
Settings · Docs · Powered by Private Packagist |
The mageos-3 recipe now copies the project's patches/ directory into the build context BEFORE composer install (ho-nl/deployyy#5), so a patch here is applied by vaimo/composer-patches during the install. Say so next to the other committed-on-purpose files, with the one rule that matters: a patch the plugin cannot apply fails the build, but a patch it never sees (wrong directory, wrong package target) is a silent no-op — verify in the image. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Sansec: StyleSmuggler (2026-09-05) — unauthenticated RCE in every Magento Open Source / Adobe Commerce / Mage-OS release up to 2.4.9, exploited in the wild since 2026-09-04, no vendor fix (Adobe's next bulletin is 2026-09-08). Attacker-controlled text reaches the email template filter; its
{{block}}directive drives a method chain into the DI compiler's code scanners, whoseinclude/requirethen executes a poisonedvar/reportorvar/logfile (mechanism).What
patches/stylesmuggler-di-scanner-guard.patch— the disrex-group mitigation, targeted atmage-os/magento2-base:ArrayScanner,ClassesScannerandXmlInterceptorScannerthrow on any non-CLI SAPI (they only run fromsetup:di:compile). Dry-run verified against Mage-OS 3.4 files.vaimo/composer-patches ^6.0(require +allow-plugins),extra.patches-search: patches.composer.lockupdated for that package only (composer update vaimo/composer-patches --no-install: adds vaimo/composer-patches, vaimo/topological-sort, loophp/phposinfo — nothing else moves). Every project scaffolded from this template inherits both.Built by the deployyy
mageos-3recipe, which today copies onlycomposer.json/composer.lockbeforecomposer install—patches/is not in the context at install time, so the plugin silently applies nothing. Companion PR ho-nl/deployyy ("recipe copies the project's patches/ before composer install") fixes that; merge it first. Until then this PR is inert, never harmful.Remove the patch once the vendor fix is in. Same change in ho-nl/project-mageos-demo.
🤖 Generated with Claude Code
https://claude.ai/code/session_011JswXZJpSwdNGYpXuBiYq2
Generated by Claude Code