The PolyShell flaw, tracked in Adobe advisory APSB25-94, allows unauthenticated attackers to use Magento Open Source and Adobe Commerce guest-cart REST API requests to upload attacker-controlled image polyglot files into pub/media/custom_options/. The issue affects production releases reportedly through 2.4.9-alpha2 and stems from validation that accepts image content and MIME types without enforcing that the supplied filename extension matches the validated image format.
Remote code execution is possible when Apache or Nginx exposes the custom-options upload path and permits PHP execution there. Even where server configuration prevents execution, attackers can persist arbitrary files in the directory and may obtain stored XSS if uploaded content is web-accessible. Organizations should apply Adobe’s relevant remediation, ensure upload directories cannot execute scripts or be directly exposed, and investigate pub/media/custom_options/ for unexpected non-image files before making web-server configuration changes.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Sansec published research identifying PolyShell (APSB25-94), an unauthenticated unrestricted file-upload flaw in Magento Open Source and Adobe Commerce. The issue permits persistent placement of attacker-controlled image-valid polyglot files through the guest-cart REST API; remote code execution depends on unsafe web-server configuration.
The issue is indicated as addressed in Magento version 2.4.9-alpha3. No release date for that version is provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.