GHSA-xcwx-r2gw-w93m

Suggest an improvement
Source
https://github.com/advisories/GHSA-xcwx-r2gw-w93m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xcwx-r2gw-w93m
Aliases
Published
2026-03-11T00:13:41Z
Modified
2026-03-13T10:56:25Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Sylius has a DQL Injection via API Order Filters
Details

Impact

Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can inject arbitrary DQL:

GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC

Patches

The issue is fixed in versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, 2.2.3 and above.

Workarounds

An EventSubscriber that sanitizes order query parameters only on API routes before they reach the vulnerable filters.

The subscriber accepts an $apiRoute constructor parameter (default /api/v2) and skips non-API requests entirely — so there is zero overhead on shop/admin page requests.

This follows the same pattern used by Sylius's own KernelRequestEventSubscriber (src/Sylius/Bundle/ApiBundle/EventSubscriber/KernelRequestEventSubscriber.php), which also uses str_contains($pathInfo, $this->apiRoute) to scope logic to API routes.


Step 1 — Create the EventSubscriber

src/EventSubscriber/SanitizeOrderDirectionSubscriber.php:

<?php

declare(strict_types=1);

namespace App\EventSubscriber;

use Symfony\Component\EventDispatcher\EventSubscriberInterface;
use Symfony\Component\HttpKernel\Event\RequestEvent;
use Symfony\Component\HttpKernel\KernelEvents;

final class SanitizeOrderDirectionSubscriber implements EventSubscriberInterface
{
    private const ALLOWED_DIRECTIONS = ['asc', 'desc'];

    public function __construct(
        private string $apiRoute,
    ) {
    }

    public static function getSubscribedEvents(): array
    {
        return [
            KernelEvents::REQUEST => ['sanitizeOrderParameters', 64],
        ];
    }

    public function sanitizeOrderParameters(RequestEvent $event): void
    {
        if (!str_contains($event->getRequest()->getPathInfo(), $this->apiRoute)) {
            return;
        }

        $request = $event->getRequest();

        /** @var mixed $order */
        $order = $request->query->all()['order'] ?? null;
        if (!is_array($order)) {
            return;
        }

        $needsSanitization = false;
        $sanitized = [];
        foreach ($order as $field => $direction) {
            if (is_string($direction) && in_array(strtolower($direction), self::ALLOWED_DIRECTIONS, true)) {
                $sanitized[$field] = $direction;
            } else {
                $needsSanitization = true;
            }
        }

        if (!$needsSanitization) {
            return;
        }

        $all = $request->query->all();
        $all['order'] = $sanitized;
        $request->query->replace($all);

        $request->server->set('QUERY_STRING', http_build_query($all));
        $request->attributes->set('_api_filters', $all);
    }
}

Step 2 — Register the service

Option A — If your config/services.yaml already has App\ autowiring (Symfony default):

# Nothing to do — autoconfigure picks up EventSubscriberInterface automatically.
# Optionally bind the API route prefix:
services:
    App\EventSubscriber\SanitizeOrderDirectionSubscriber:
        arguments:
            $apiRoute: '%sylius.security.new_api_route%'

Option B — If there is no App\ autowiring:

services:
    App\EventSubscriber\SanitizeOrderDirectionSubscriber:
        arguments:
            $apiRoute: '%sylius.security.new_api_route%'
        tags: ['kernel.event_subscriber']

Using %sylius.security.new_api_route% ties the subscriber to the same prefix Sylius uses (/api/v2 by default). If the parameter is not available, hardcode '/api/v2' instead.

Step 3 — Clear cache

bin/console cache:clear

Reporters

We would like to extend our gratitude to the following individuals for their detailed reporting and responsible disclosure of this vulnerability:

  • Chris Alupului (@Neosprings)
  • Bartłomiej Nowiński (@bnBart)

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids":  [
        "CWE-89",
        "CWE-943"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-11T00:13:41Z",
    "nvd_published_at":  "2026-03-10T22:16:20Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.12

Affected versions

v0.*
v0.1.0
v0.2.0
v0.3.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.10.0
v0.11.0
v0.12.0
v0.13.0
v0.14.0
v0.15.0
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v1.*
v1.0.0-alpha.1
v1.0.0-alpha.2
v1.0.0-beta.1
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-rc.1
v1.0.0-rc.2
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.0.10
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.0.15
v1.0.16
v1.0.17
v1.0.18
v1.1.0-RC
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.1.8
v1.1.9
v1.1.10
v1.1.11
v1.1.12
v1.1.13
v1.1.14
v1.1.15
v1.1.16
v1.1.17
v1.1.18
v1.2.0-BETA
v1.2.0-RC
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v1.2.10
v1.2.11
v1.2.12
v1.2.13
v1.2.14
v1.2.15
v1.2.16
v1.2.17
v1.3.0-BETA
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.3.8
v1.3.9
v1.3.10
v1.3.11
v1.3.12
v1.3.13
v1.3.14
v1.3.15
v1.3.16
v1.4.0-BETA.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.4.10
v1.4.11
v1.4.12
v1.5.0-RC.1
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.5.6
v1.5.7
v1.5.8
v1.5.9
v1.6.0-ALPHA.1
v1.6.0-ALPHA.2
v1.6.0-RC.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.6.6
v1.6.7
v1.6.8
v1.6.9
v1.7.0-ALPHA.1
v1.7.0-ALPHA.2
v1.7.0-RC.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.7.6
v1.7.7
v1.7.8
v1.7.9
v1.7.10
v1.7.11
v1.8.0-RC.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v1.8.10
v1.8.11
v1.8.12
v1.9.0-ALPHA.1
v1.9.0-BETA.1
v1.9.0-ALPHA.2
v1.9.0-BETA.2
v1.9.0-BETA.3
v1.9.0-RC.1
v1.9.0-RC.2
v1.9.0
v1.9.1
v1.9.2
v1.9.3
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9
v1.9.10
v1.9.11

Database specific

last_known_affected_version_range
"<= 1.9.11"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.10.0
Fixed
1.10.16

Affected versions

v1.*
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.10.6
v1.10.7
v1.10.8
v1.10.9
v1.10.10
v1.10.11
v1.10.12
v1.10.13
v1.10.14
v1.10.15

Database specific

last_known_affected_version_range
"<= 1.10.15"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.11.0
Fixed
1.11.17

Affected versions

v1.*
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.11.6
v1.11.7
v1.11.8
v1.11.9
v1.11.10
v1.11.11
v1.11.12
v1.11.13
v1.11.14
v1.11.15
v1.11.16

Database specific

last_known_affected_version_range
"<= 1.11.16"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.12.0
Fixed
1.12.23

Affected versions

v1.*
v1.12.0
v1.12.1
v1.12.2
v1.12.3
v1.12.4
v1.12.5
v1.12.6
v1.12.7
v1.12.8
v1.12.9
v1.12.10
v1.12.11
v1.12.12
v1.12.13
v1.12.14
v1.12.15
v1.12.16
v1.12.17
v1.12.18
v1.12.19
v1.12.20
v1.12.21
v1.12.22

Database specific

last_known_affected_version_range
"<= 1.12.22"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.13.0
Fixed
1.13.15

Affected versions

v1.*
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.13.7
v1.13.8
v1.13.9
v1.13.10
v1.13.11
v1.13.12
v1.13.13
v1.13.14

Database specific

last_known_affected_version_range
"<= 1.13.14"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.14.0
Fixed
1.14.18

Affected versions

v1.*
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.14.7
v1.14.8
v1.14.9
v1.14.10
v1.14.11
v1.14.12
v1.14.13
v1.14.14
v1.14.15
v1.14.16
v1.14.17

Database specific

last_known_affected_version_range
"<= 1.14.17"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.0.16

Affected versions

v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.8
v2.0.9
v2.0.10
v2.0.11
v2.0.12
v2.0.13
v2.0.14
v2.0.15

Database specific

last_known_affected_version_range
"<= 2.0.15"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1.0
Fixed
2.1.12

Affected versions

v2.*
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9
v2.1.10
v2.1.11

Database specific

last_known_affected_version_range
"<= 2.1.11"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"
sylius/sylius

Package

Name
sylius/sylius
Purl
pkg:composer/sylius/sylius

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.2.0
Fixed
2.2.3

Affected versions

v2.*
v2.2.0
v2.2.1
v2.2.2

Database specific

last_known_affected_version_range
"<= 2.2.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-xcwx-r2gw-w93m/GHSA-xcwx-r2gw-w93m.json"