Authorization Bypass Through User-Controlled Key Affecting sylius/sylius package, versions >=2.0.0-alpha.1, <2.0.16>=2.1.0, <2.1.12>=2.2.0, <2.2.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-SYLIUSSYLIUS-15460801
  • published11 Mar 2026
  • disclosed11 Mar 2026
  • creditPeter Stockli, Man Yue Mo

Introduced: 11 Mar 2026

CVE-2026-31820  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade sylius/sylius to version 2.0.16, 2.1.12, 2.2.3 or higher.

Overview

sylius/sylius is a platform for PHP, based on Symfony framework.

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via unvalidated resource IDs accepted through #[LiveArg] parameters in multiple LiveComponents. An attacker can access sensitive information belonging to other users by supplying arbitrary resource IDs to actions such as addressFieldUpdated and refreshCart, which load resources without verifying ownership. This may expose personal address details and order information.

CVSS Base Scores

version 4.0
version 3.1