GHSA-m5f5-28qr-9g9r

Suggest an improvement
Source
https://github.com/advisories/GHSA-m5f5-28qr-9g9r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m5f5-28qr-9g9r/GHSA-m5f5-28qr-9g9r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m5f5-28qr-9g9r
Aliases
Published
2026-07-10T20:36:56Z
Modified
2026-07-10T20:56:35Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
Details

Impact

A PHP Object Injection vulnerability affects the PrestaShop module ps_facetedsearch.

The module rebuilds the selected search filters from the request URL. The value of a slider filter (price or weight) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native unserialize(). By crafting that value, an attacker can smuggle a malicious serialized PHP object into the cache. When it is deserialized, a gadget chain writes an arbitrary PHP file inside the module directory, which is then used as a webshell to run commands on the server.

Who is impacted

Any shop using a vulnerable version of ps_facetedsearch that displays a filter template containing a slider filter (price or weight). Exploitation is remote and unauthenticated, a single crafted front-office request is enough, and leads to remote code execution and full compromise of the shop and its server.

Affected versions: 3.0.0 through 4.0.3 (all versions since 3.0.0, including the latest release).

Patches

Upgrade the ps_facetedsearch module to the patched version. Upgrading the module is the best action that removes the vulnerability.

Otherwise, you can apply the fix manually in the file src/Filters/Block.php:

In the getFromCache() method, replace the native unserialize() call:

// Before
if (!empty($row)) {
    return unserialize(current($row));
}

// After
if (!empty($row)) {
    return \Tools::unSerialize(current($row));
}

Until the module is upgraded:

  • Remove price and weight slider filters from the filter templates that are exposed on the front office.
  • Clear the faceted-search filter cache, and audit the modules/ps_facetedsearch/ directory for unexpected PHP files.
  • Monitor search requests for PHP serialization patterns (O:, ;i:, references to classes such as Monolog\…) and block them at the WAF level.

Resources

  • Thank you to Frédéric Moreau (Antadis) and Gilles Caudal (Datalinx) for reporting this vulnerability.
Database specific
{
    "cwe_ids":  [
        "CWE-74"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-10T20:36:56Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Packagist / prestashop/ps_facetedsearch

Package

Name
prestashop/ps_facetedsearch
Purl
pkg:composer/prestashop/ps_facetedsearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
4.0.4

Affected versions

v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.1.0
v3.2.0
v3.2.1
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.6.0
v3.7.0
v3.7.1
v3.8.0
v3.9.0
v3.10.0
v3.11.0
v3.11.1
v3.12.0
v3.12.1
v3.13.0
v3.13.1
v3.13.2
v3.14.0
v3.14.1
v3.15.0
v3.15.1
v3.16.0
v3.16.1
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-m5f5-28qr-9g9r/GHSA-m5f5-28qr-9g9r.json"