CVE Explorer
CVE-2026-25758
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their order by manipulating address ID parameters. This enables unauthorized access to other guests' personally identifiable information (PII) including names, addresses and phone numbers. The vulnerability bypasses existing ownership validation checks and affects all guest checkout trans
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"spree","vendor":"spree","versions":[{"status":"affected","version":"< 4.10.3"},{"status":"affected","version":">= 5.0.0, < 5.0.8"},{"status":"affected","version":">= 5.1.0.beta, < 5.1.10"},{"status":"affected","version":">= 5.2.0.rc1, < 5.2.7"},{"status":"affected","version":">= 5.3.0.rc2, < 5.3.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/problemTypes/1/descriptions/0
Source references
10 source assertions{"name":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/address_book.rb#L16-L38","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/address_book.rb#L16-L38"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/6
{"name":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/checkout.rb#L241-L254","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/checkout.rb#L241-L254"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/7
{"name":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/services/spree/checkout/update.rb#L33-L48","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/services/spree/checkout/update.rb#L33-L48"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/8
{"name":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/lib/spree/permitted_attributes.rb#L92-L96","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/lib/spree/permitted_attributes.rb#L92-L96"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/9
{"name":"https://github.com/spree/spree/commit/15619618e43b367617ec8d2d4aafc5e54fa7b734","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/commit/15619618e43b367617ec8d2d4aafc5e54fa7b734"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/1
{"name":"https://github.com/spree/spree/commit/29282d1565ba4f7bc2bbc47d550e2c0c6d0ae59f","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/commit/29282d1565ba4f7bc2bbc47d550e2c0c6d0ae59f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/2
{"name":"https://github.com/spree/spree/commit/6650f96356faa0d16c05bcb516f1ffd5641741b8","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/commit/6650f96356faa0d16c05bcb516f1ffd5641741b8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/3
{"name":"https://github.com/spree/spree/commit/902d301ac83fd2047db1b9a3a99545162860f748","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/commit/902d301ac83fd2047db1b9a3a99545162860f748"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/4
{"name":"https://github.com/spree/spree/commit/ff7cfcfcfe0c40c60d03317e1d0ee361c6a6b054","tags":["x_refsource_MISC"],"url":"https://github.com/spree/spree/commit/ff7cfcfcfe0c40c60d03317e1d0ee361c6a6b054"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/5
{"name":"https://github.com/spree/spree/security/advisories/GHSA-87fh-rc96-6fr6","tags":["x_refsource_CONFIRM"],"url":"https://github.com/spree/spree/security/advisories/GHSA-87fh-rc96-6fr6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c5967f5cbb990709cfdd16ea886bb6c85b6451ea372501c9b4210cf9aa45f4a5 · sha256:88ebcc1548fef7ac… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.