<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:00:23.669198+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-267662</id>
    <title>EUVD-2026-267662</title>
    <updated>2026-10-06T19:00:23.715355+00:00</updated>
    <content>EUVD-2026-267662</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-267662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25757</id>
    <title>fkie_cve-2026-25757</title>
    <updated>2026-10-06T19:00:23.715393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This issue has been patched in versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-25757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p6pv-q7rc-g4h9</id>
    <title>GHSA-p6pv-q7rc-g4h9 — Unauthenticated Spree Commerce users can view completed guest orders by Order ID</title>
    <updated>2026-10-06T19:00:23.715425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: spree_storefront</p>
<p>### Unauthenticated users can view completed guest orders by Order ID (`GHSL-2026-029`)</p>
<p>The `OrdersController#show` action permits viewing completed guest orders by order number alone, without requiring the associated order token.</p>
<p>Order lookup without enforcing token requirement in [`OrdersController#show`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L14):</p>
<p>```ruby
@order = complete_order_finder.new(number: params[:id], token: params[:token], store: current_store).execute.first
```</p>
<p>Authorization bypass for guest orders in [`authorize_access`](https://github.com/spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/storefront/app/controllers/spree/orders_controller.rb#L51C1-L55C8):
```ruby
def authorize_access
  return true if @order.user_id.nil?</p>
<p>@order.user == try_spree_current_user
end
```</p>
<p>If the attacker is in possession of a leaked Order ID, they might look it up directly via this API.
Alternatively, brute forcing all or parts of the possible Order IDs might be feasible for an attacker. (The Order IDs themselves are [securely generated](https://github.com/spree/spree/blob/a878eb4a782ce0445d218ea86fb12075b0e3d7cc/core/lib/spree/core/number_generator.rb#L45), but with relatively low entropy: by default an order ID has a length of 9 and a base of 10, that would require an attacker to perform 1 billion requests to gather all guest orders. (At an assumed constant rate of 100 reque…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p6pv-q7rc-g4h9"/>
  </entry>
</feed>
