CVE-2026-53787 is a critical unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 affecting versions before 4.0.0. The flaw is present in the extension's upload endpoint used by the Single File Upload attribute type. The endpoint accepts direct POST requests without requiring authentication, session validation, or cart context, and it fails to properly restrict uploaded file types or sanitize attacker-controlled filenames. As a result, an unauthenticated attacker can upload arbitrary files to the store's media directory. The issue includes unrestricted upload of dangerous file types and, in affected versions, insufficient filename validation that can permit directory traversal beyond the intended upload location. On deployments where the media directory allows PHP execution, the vulnerability can be turned into remote code execution by uploading a server-executable script. Where code execution is not possible, the flaw still enables malicious content hosting and client-side payload delivery such as stored cross-site scripting through uploaded HTML or SVG content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Single-file Python exploit for mass exploitation of an Adobe Commerce/Magento issue referenced as APSB25-94. The script is not a framework module; it is a standalone concurrent scanner/exploit tool with CLI options for target list input, thread count, output files, TLS verification disabling, SKU selection, verbosity, and request delay. Its core purpose is to automate exploitation across many hosts by crawling or selecting product targets, then uploading a crafted polyglot GIF that embeds a PHP webshell. The embedded payload is the most important capability: it is a minimal PHP webshell appended to a valid GIF header so the file can masquerade as an image while still executing as PHP if placed in an executable context. Once deployed, the shell supports two functions: command execution through the GET parameter 'c' using system/exec/shell_exec/passthru, and arbitrary file upload through the GET parameter 'up', which renders a multipart upload form and stores uploaded files using move_uploaded_file(). Repository structure is trivial: one Python file containing banner/UI code, HTTP client logic, concurrency via ThreadPoolExecutor, progress display via tqdm, optional requests/colorama support, and result logging. The script writes confirmed shell URLs to success.txt and partial upload-only results to uploaded.txt. It includes SSL-insecure mode, custom User-Agent, and multi-target orchestration, indicating practical offensive use rather than a simple proof-of-concept. Because the payload is hardcoded but functional, maturity is best classified as OPERATIONAL. Notable caveat: the file/banner and docstring contain inconsistent identifiers, mentioning both CVE-2026-53587 and CVE-2026-53787. The exploit clearly intends to target Adobe Commerce/Magento via APSB25-94, but the exact CVE label in the repository appears inconsistent.
This repository is a small standalone exploit repo for CVE-2026-53787, an unauthenticated arbitrary file upload flaw in the Amasty Order Attributes extension for Magento 2 before 4.0.0. The repo contains only two files: a README describing the vulnerability and affected REST endpoints, and a single Python exploit script, poc.py, which is the operational entry point. The exploit script supports bulk targeting from a file of domains using 20 concurrent threads. It first attempts a proof-of-concept upload by sending JSON with base64-encoded file content to three Magento REST endpoints: /rest/V1/amasty_orderattr/uploadFile, /rest/all/V1/amasty_orderattr/uploadFile, and /rest/default/V1/amasty_orderattr/uploadFile. After upload, it probes likely public media paths under /media/amasty_checkout/ and /pub/media/amasty_checkout/ to locate the uploaded file. In full exploitation mode, the script escalates from simple file upload verification to remote code execution by uploading multiple PHP webshell variants across several executable extensions (.php, .php5, .phtml, .phar, .inc, .php7, .php8, .pht). It then tests each discovered shell with query parameters c, cmd, x, and p using the id command to confirm execution. One advanced PHP shell also supports reading files, writing arbitrary files from base64 data, downloading files, and uploading additional files, making post-exploitation more capable than a minimal command shell. A notable and high-risk finding is that the Python script contains unrelated malicious behavior against the operator: on startup it decodes and executes a hardcoded bash reverse-shell command locally via subprocess.Popen, causing the machine running the exploit to attempt a callback to 146.70.240.206:62208. This indicates the repository is not just an exploit for remote targets but also contains a trojanized component that compromises the user executing it. Overall, this is a real exploit rather than a detector. Its main capabilities are unauthenticated arbitrary file upload, public file placement verification, webshell deployment, and RCE confirmation against vulnerable Magento/Amasty installations, while also embedding a malicious local reverse-shell launcher.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific vulnerability identified as CVE-2026-53787. The content indicates documentation was added covering description, impact, remediation, and HTTP request flow for exploitation, but does not provide technical specifics.
An unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 before version 4.0.0 that can allow arbitrary file writes and potentially remote code execution if uploaded PHP files can execute in the media directory.
A critical unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 that can lead to remote code execution, path traversal, malware hosting, and stored XSS depending on server configuration and version.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.