UPSTREAM FIX

magento2-40248: GraphQL updateCartItems response still listing removed cart items

Community fix magento2-40248 merged into magento/magento2 on 2026-03-05, released in 2.4.9.

Fixes GraphQL updateCartItems response still listing removed cart items edited

Pull request title
Call RemoveItem on cart instead of ItemRepository
Pull request
magento/magento2#40248
Issues
#40255 pr-derived
Author
@indykoning
Merged
2026-03-05
Fixed in
2.4.9
Reported on
—
Categories
GraphQL, Shopping Cart
Components
magento/module-quote-graph-ql

Labels

Area
Cart & Checkout
Component
GraphQL
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

This PR replaces the deleteById calls on the CartItemRepository with removeItem on the cart instance.
This makes sure expected observers are triggered and the item is actually updated on the cart object as well, instead of in the database only.

Steps to reproduce

1. Add multiple products to the cart
2. remove the products with the following query
mutation updateCart($input: UpdateCartItemsInput) {
  updateCartItems(input: $input) {
    cart {
      items {
        uid
      }
    }
  }
}

{
  "input": {
    "cart_id": "xxxx",
    "cart_items": [
      {
        "cart_item_id": "xx",
        "quantity": 0
      },
      {
        "cart_item_id": "xx",
        "quantity": 0
      },
      {
        "cart_item_id": "xx",
        "quantity": 0
      },
      {
        "cart_item_id": "xx",
        "quantity": 0
      },
      {
        "cart_item_id": "xx",
        "quantity": 0
      }
    ]
  }
}
3. Observe how items still appear to be in the cart until you manually request the cart again.
4. Repeat these steps after applying this PR
5. Observe how all selected items have immediately disappeared from the response.

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 conflict 2.4.6-p1 conflict 2.4.6-p2 conflict 2.4.6-p3 conflict 2.4.6-p4 conflict 2.4.6-p5 conflict 2.4.6-p6 conflict 2.4.6-p7 conflict 2.4.6-p8 conflict 2.4.6-p9 conflict 2.4.6-p10 conflict 2.4.6-p11 conflict 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 conflict 2.4.7-p1 conflict 2.4.7-p2 conflict 2.4.7-p3 conflict 2.4.7-p4 conflict 2.4.7-p5 conflict 2.4.7-p6 conflict 2.4.7-p7 conflict 2.4.7-p8 conflict 2.4.7-p9 conflict 2.4.7-p10 conflict
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflict 2.4.8-p1 conflict 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 94.0%. Probability it is security relevant: 0.7%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 95.4%, refactor 3.0%, tests_only 0.7%, feature 0.5%, dependency 0.3%, docs_only 0.2%89.3%
Areagraphql_apigraphql_api 61.7%, checkout 36.2%, framework 0.5%44.2%
Reported versionunspecifiedunspecified 26.6%, 2.4.6 4.5%, 2.4.7 1.9%6.9%
Scope1.06 of 21 49.9%, 2 27.8%, 0 22.3%6.4%
Risk1.06 of 22 38.9%, 0 33.0%, 1 28.1%0.9%
Worth backporting1.60 of 22 68.2%, 1 23.8%, 0 7.9%29.3%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40248/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

No checked release lacks this fix with a clean code match, so no bundle is offered.

Bundle README (what the ZIP ships)
# magento2-40248

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40248
Issue: https://github.com/magento/magento2/issues/40255
Author: @indykoning
Source commit: 9d9149b0d3e9859037dbdd8cef433422128efdc9
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.