


Perceptive Security
SOC/SIEM Consultancy

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a h…
Published:
19 April 2026 at 22:00:00
Alert date:
20 April 2026 at 18:01:58
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Magento Long Term Support (LTS) versions prior to 20.17.0 contain a vulnerability where PHP functions like getimagesize(), file_exists(), and is_readable() can trigger deserialization when processing phar:// stream wrapper paths. The vulnerability occurs during image validation and media handling processes. Attackers can exploit this by uploading malicious phar files disguised as images and triggering these functions with phar:// paths to achieve arbitrary code execution. This affects the community-driven alternative to Magento Community Edition e-commerce platform. Version 20.17.0 patches this issue.
Technical details
Mitigation steps:
Affected products:
Magento Long Term Support (LTS)
OpenMage LTS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-25524
https://github.com/OpenMage/magento-lts/releases/tag/v20.17.0
https://github.com/OpenMage/magento-lts/security/advisories/GHSA-fg79-cr9c-7369
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
