This GitHub repository offers a security module for Magento 2 that disables the unauthenticated customer address file upload endpoint, addressing vulnerabilities that could lead to remote code execution, especially related to a critical vulnerability known as "SessionReaper." It emphasizes the risks associated with arbitrary file uploads, even on patched systems.
11 Nov 2025