Shared on Mage Dispatch · 07 Sep 2026
StyleSmuggler 0-day — DI Scanner CLI-Only Patch
Patch enforcing CLI-only execution for DI scanners to mitigate StyleSmuggler, adding PHP_SAPI checks in ArrayScanner, ClassesScanner, and XmlInterceptorScanner.
Shared on Mage Dispatch · 07 Sep 2026
Patch enforcing CLI-only execution for DI scanners to mitigate StyleSmuggler, adding PHP_SAPI checks in ArrayScanner, ClassesScanner, and XmlInterceptorScanner.
Auto-disables 2FA in developer mode and adds admin/CLI toggles to enable or disable 2FA—and API token generation—in other environments.
Three bash scripts to scan for IoCs and guide cleanup on servers, apply community mitigations via Composer patches and a hardening module, and remotely check GraphQL exposure. Includes DDEV/Warden support, cloud-friendly usage, and step-by-step confirmations.
Diff introduces SecurePathValidator to reject stream/writable paths during template rendering, blocks backend/adminhtml blocks in {{block}} directives, and neutralizes PHP tags in error reports. Also tightens DI/setup scanners and grid URL generator type checks to avoid unsafe class/path resolution.
Mage Dispatch is a community-run archive and bi-weekly newsletter for the Magento, Adobe Commerce and Mage-OS ecosystem. Modules, articles, security advisories and tools, hand-picked by developers and shared so good work does not disappear into the void.
Browse the latest links → Explore by topic → Submit a link → About us →