CVE-2026-68501: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Two unauthenticated Mollie shop endpoints look up orders by a sequential integer orderId
with no ownership or session check. Chained, they expose customer PII.
GET /{_locale}/thank-you (PageRedirectController::thankYouAction, route
sylius_mollie_shop_thank_you_page_redirect) loads the order with findOneBy(['id' => $orderId])
and returns a 302 whose Location header carries that order’s tokenValue. Any orderId
thus yields that order’s token. A non-existent id dereferences null and returns a 500. The
handler also writes the raw orderId into the session.
GET /{_locale}/get-code (QrCodeAction::fetchQrCodeFromOrder, route
sylius_mollie_shop_get_qr_code) runs the same lookup and returns the order’s QR code and id
as JSON, ignoring the session cart; this is where the front-end got the integer id. A bad id
500s here too.
That tokenValue is the order’s only access control. Passed to the Sylius core page
GET /{_locale}/register-after-checkout/{tokenValue} it returns a form pre-filled with the
customer’s first name, last name and email. The full attack: enumerate orderId, read the
token from the redirect, read the PII, at roughly a 1-in-71 hit rate for guest orders.
register-after-checkout is Sylius core, not the plugin, and trusts the token by design, so
the leak is what must be fixed.
None of the plugin endpoints require a login, session or CSRF token.
References
- github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49
- github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267
- github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a
- github.com/Sylius/MolliePlugin/pull/351
- github.com/Sylius/MolliePlugin/pull/352
- github.com/Sylius/MolliePlugin/pull/354
- github.com/Sylius/MolliePlugin/releases/tag/v2.2.8
- github.com/Sylius/MolliePlugin/releases/tag/v3.2.4
- github.com/Sylius/MolliePlugin/releases/tag/v3.3.1
- github.com/Sylius/MolliePlugin/security/advisories/GHSA-x83g-979r-f5fh
- github.com/advisories/GHSA-x83g-979r-f5fh
- nvd.nist.gov/vuln/detail/CVE-2026-68501
Code Behaviors & Features
Detect and mitigate CVE-2026-68501 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →