The latest in Magento land
Do you know that feeling? You worked long and hard on that blog post? Or that super wicked Magento extension? And then you hit publish and... nothing. No one reads it. No one sees it. It just sits there. Well, not anymore! Mage Dispatch is here to help you get your content out there.
Mage Dispatch is a newsletter for the community and by the community. Here you can share links that you think that the community should know about. We will include it in our next newsletter.
Heads up
StyleSmuggler
Critical unauthenticated RCE in the Magento template engine, CVSS 10 and actively exploited. Install both patches below right now, then check your store for compromise.
-
https://github.com/rubenzantingh/claude-code-magento-agents
A comprehensive collection of specialized Claude Code agents designed to optimize Magento 2 development workflows. This repository contains 30+ expert agents organized into 7 categories, each providing deep domain expertise for specific aspects of Magento 2 development. Keep in mind this repository is very much a work in progress. Please report any particulars by means of a Github issue.
31122 -
https://www.sdj.pw/posts/magento2-patching/
Deploying patches is simple for in-house development teams or smaller Agencies maintaining only a few stores. Manually applying patches per project is simple, but doesn’t scale well. Both from time cost and security exposure perspectives.
-
https://www.sdj.pw/posts/magento2-session-reaper-cve-2025-54236/
How to guide on checking if your Magento 2 store is safe from the Session Reaper (CVE-2025-54236) exploit. And guidance on how to patch and secure your site if it is not.
-
https://maxchadwick.xyz/blog/shutting-down-file-upload-controllers-for-session-reaper-is-futile
Since Searchlight Cyber published a technical write up and proof-of-concept for the SessionReaper vulnerability, attackers have been mass scanning Magento / Adobe Commerce stores for vulnerable targets. The first phase of the attack involves uploading a payload containing malicious session data to the server.
-
https://github.com/DeployEcommerce/module-prevent-customer-address-file-upload
This is a Magento 2 extension that prevents file uploads to /customer/address_file/upload endpoint which is used in combination with an flaw in Magento's logic to upload code and then execute it for CVE-2025-54236.
28 -
https://github.com/boxtwentytwo/m2-cloudflare-turnstile
A module for Magento 2 that extends the built-in reCAPTCHA support to add Cloudflare Turnstile, an alternative privacy-friendly solution.
513 -
https://github.com/dadolun95/magento2-hreflang
This module manages alternate URLs for homepages, CMS pages, product pages, and category pages.
16 -
https://github.com/zero1limited/Zero1_OpenPos
We created OpenPOS to solve some headaches experienced by a few of our wonderful customers. The profound set of circumstances around timing and speed of delivery caused us to quickly widen our horizons and produce a fully Open Source EPOS.
512 -
https://github.com/tddwizard/magento2-fixtures
A goodie but oldie: An alternative to the procedural script based fixtures in Magento 2 integration tests. It aims to be: extensible, expressive, easy to use
34147 -
https://github.com/rubenzantingh/RubenZantingh_AdminModuleList
This module provides a comprehensive overview of installed and active modules within your Magento instance.
12