🛡️ CVE-2026-31825 — sylius

🟡 CVSS 5.3 — Medium ✅ No Known Exploit CWE-89 NVD
5.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Sylius has a DQL Injection via API Order Filters

Impact

Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can inject arbitrary DQL:

```

GET /api/v2/shop/products?order[price]=ASC,%20variant.code%20DESC

```

Patches

The issue is fixed in versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, 2.2.3 and above.

Workarounds

An EventSubscriber that sanitizes order query parameters only on API routes before they reach the vulnerable filters.

The subscriber accepts an $apiRoute constructor parameter (default /api/v2) and skips non-API requests entirely — so there is zero overhead on shop/admin page requests.

This follows the same pattern used by Sylius's own KernelRequestEventSubscriber (src/Sylius/Bundle/ApiBundle/EventSubscriber/KernelRequestEventSubscriber.php), which also uses str_contains($pathInfo, $this->apiRoute) to scope logic to API routes.

Step 1 — Create the EventSubscriber

src/EventSubscriber/SanitizeOrderDirectionSubscriber.php:

```php

<?php

declare(strict_types=1);

namespace App\EventSubscriber;

use Symfony\Component\EventDispatcher\EventSubscriberInterface;

use Symfony\Component\HttpKernel\Event\RequestEvent;

use Symfony\Component\HttpKernel\KernelEvents;

final class SanitizeOrderDirectionSubscriber implements EventSubscriberInterface

{

private const ALLOWED_DIRECTIONS = ['asc', 'desc'];

public function __construct(

private string $apiRoute,

) {

}

public static function getSubscribedEvents(): array

{

return [

KernelEvents::REQUEST => ['sanitizeOrderParameters', 64],

];

}

public function sanitizeOrderParameters(RequestEvent $event): void

{

if (!str_contains($event->getRequest()->getPathInfo(), $this->apiRoute)) {

return;

}

$request = $event->getRequest();

/** @var mixed $order */

$order = $request->query->all()['order'] ?? null;

if (!is_array($order)) {

return;

}

$needsSanitization = false;

$sanitized = [];

foreach ($order as $field => $direction) {

if (is_string($direction) && in_array(strtolower($direction), self::ALLOWED_DIRECTIONS, true)) {

$sanitized[$field] = $direction;

} else {

$needsSanitization = true;

}

}

if (!$needsSanitization) {

return;

}

$all = $request->query->all();

$all['order'] = $sanitized;

$request->query->replace($all);

$request->server->set('QUERY_STRING', http_build_query($all));

$request->attributes->set('_api_filters', $all);

}

}

```

Step 2 — Register the service

Option A — If your config/services.yaml already has App\ autowiring (Symfony default):

```yaml

# Nothing to do — autoconfigure picks up EventSubscriberInterface automatically.

# Optionally bind the API route prefix:

services:

App\EventSubscriber\SanitizeOrderDirectionSubscriber:

arguments:

$apiRoute: '%sylius.security.new_api_route%'

```

Option B — If there is no App\ autowiring:

```yaml

services:

App\EventSubscriber\SanitizeOrderDirectionSubscriber:

arguments:

$apiRoute: '%sylius.security.new_api_route%'

tags: ['kernel.event_subscriber']

```

Using %sylius.security.new_api_route% ties the subscriber to the same prefix Sylius uses (/api/v2 by default). If the parameter is not available, hardcode '/api/v2' instead.

Step 3 — Clear cache

```bash

bin/console cache:clear

```

Reporters

We would like to extend our gratitude to the following individuals for their detailed reporting and responsible disclosure of this vulnerability:

  • Chris Alupului (@Neosprings)
  • Bartłomiej Nowiński (@bnBart)

For more information

If you have any questions or comments about this advisory:

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality low, integrity none, availability none.

Weakness class

CVE-2026-31825 is classified as CWE-89: SQL Injection. Untrusted input is concatenated into an SQL statement, letting an attacker change the query and reach data the request should not return.

Affected software

CVE-2026-31825 is recorded against 2 packages.

  • sylius (from 2.2.0 up to 2.2.3)
  • sylius/sylius (from 2.2.0 up to 2.2.3)

Timeline and source

Published on 10 March 2026 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com

Details

Severity MEDIUM
CVSS Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE CWE-89
Public Exploit ✅ No
Source NVD
Published 2026-03-10
Updated 2026-08-12
Modified 2026-06-17
Fix URL N/A

Affected Packages

Software From version Fixed in
sylius 2.2.0 2.2.3
sylius/sylius 2.2.0 2.2.3

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in sylius

CVE-2026-31825 is rated CVSS 5.3 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.