Published Sep 9, 2025.
Improper input validation in the Web API's service input processor (CVE-2025-54236), publicly known as SessionReaper. An unauthenticated attacker can hijack customer sessions through the REST API and, depending on configuration, reach remote code execution. Adobe shipped the out-of-band hotfix VULN-32437 before the regular patch release; it was the first emergency patch since CosmicSting.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-54236 | 9.1 | improper-input-validation | security-feature-bypass | no |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-88
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →