CVE-2026-25524 PUBLISHED

OpenMage LTS's Phar Deserialization leads to Remote Code Execution

Assigner: GitHub_M
Reserved: 02.02.2026 Published: 20.04.2026 Updated: 20.04.2026

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as getimagesize(), file_exists(), and is_readable() can trigger deserialization when processing phar:// stream wrapper paths. OpenMage LTS uses these functions with potentially controllable file paths during image validation and media handling. An attacker who can upload a malicious phar file (disguised as an image) and trigger one of these functions with a phar:// path can achieve arbitrary code execution. Version 20.17.0 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor OpenMage
Product magento-lts
Versions
  • Version < 20.17.0 is affected

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE