PYSEC-2026-1890

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/saleor/PYSEC-2026-1890.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1890
Aliases
Published
2026-07-07T11:45:36Z
Modified
2026-07-07T17:47:49Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
Details

Summary

Using Pickup: Local stock only as a click-and-collect points could cause a leak of customer addresses

Details

When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address.

Impact

The vulnerability can cause the leak of customer's address when using click-and-collect delivery option marked as Local stock only. It has impact on all orders with click-and-collect delivery method marked as Pickup:Local stock only The affected versions: >=3.14.56 <3.14.61, >=3.15.31 <3.15.37, >=3.16.27 <3.16.34, >=3.17.25 <3.17.32, >=3.18.19 <3.18.28, >=3.19.5 <3.19.15 This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15

Workaround

We strongly recommend upgrading to the latest versions, in case of inability to upgrade straight away, possible workarounds are:

References

References

Affected packages

PyPI / saleor

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.14.56
Fixed
3.14.61
Introduced
3.15.31
Fixed
3.15.37
Introduced
3.16.27
Fixed
3.16.34
Introduced
3.17.25
Fixed
3.17.32
Introduced
3.18.19
Fixed
3.18.28
Introduced
3.19.5
Fixed
3.19.15

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/saleor/PYSEC-2026-1890.yaml"