Loading HuntDB...

GHSA-27wp-jvhw-v4xp

GitHub Security Advisory

Shopware vulnerable to Server Side Template Injection in Twig using deprecation silence tag

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

Shopware has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag.
It accepts as parameter a string the feature flag name to silence, but this parameter is not escaped properly and allows execution of code.

### Patches
Update to Shopware 6.6.5.1 or 6.5.8.13

### Workarounds
For older versions of 6.2, 6.3, and 6.4, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.

Affected Packages

Packagist shopware/core
Affected versions: 0 (fixed in 6.5.8.13)
Packagist shopware/platform
Affected versions: 0 (fixed in 6.5.8.13)
Packagist shopware/platform
Affected versions: 6.6.0.0 (fixed in 6.6.5.1)
Packagist shopware/core
Affected versions: 6.6.0.0 (fixed in 6.6.5.1)

Related CVEs

Key Information

GHSA ID
GHSA-27wp-jvhw-v4xp
Published
August 8, 2024 2:48 PM
Last Modified
August 8, 2024 5:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
shopware/core
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.