CVE Explorer
CVE-2026-25524
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()` can trigger deserialization when processing `phar://` stream wrapper paths. OpenMage LTS uses these functions with potentially controllable file paths during image validation and media handling. An at
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"magento-lts","vendor":"OpenMage","versions":[{"status":"affected","version":"< 20.17.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:52515207aac55bd48f1f53c7d667f74b15cc4d17470b812eeb744f92bf5a5a19 · sha256:d3803a987ea16d6e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:52515207aac55bd48f1f53c7d667f74b15cc4d17470b812eeb744f92bf5a5a19 · sha256:d3803a987ea16d6e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502: Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:52515207aac55bd48f1f53c7d667f74b15cc4d17470b812eeb744f92bf5a5a19 · sha256:d3803a987ea16d6e… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/OpenMage/magento-lts/releases/tag/v20.17.0","tags":["x_refsource_MISC"],"url":"https://github.com/OpenMage/magento-lts/releases/tag/v20.17.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52515207aac55bd48f1f53c7d667f74b15cc4d17470b812eeb744f92bf5a5a19 · sha256:d3803a987ea16d6e… · /containers/cna/references/1
{"name":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-fg79-cr9c-7369","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OpenMage/magento-lts/security/advisories/GHSA-fg79-cr9c-7369"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:52515207aac55bd48f1f53c7d667f74b15cc4d17470b812eeb744f92bf5a5a19 · sha256:d3803a987ea16d6e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.