Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-54159: PrestaShop ps_facetedsearch: Unauthenticated Remote Code Execution

CVE-2026-54159 · published 2 months ago
Summary

A vulnerability in PrestaShop's ps_facetedsearch module allows an attacker to execute code on your server without needing a login. This can happen if you're using a vulnerable version of the module and a customer or attacker crafts a specific URL request. To fix this, you should upgrade the ps_facetedsearch module to the latest version. If you can't upgrade, you can apply a manual fix by changing a line of code in the Block.php file.

What to do
  • Update prestashop ps_facetedsearch to version 4.0.4.
Affected software
Ecosystem VendorProductAffected versions
composer prestashop ps_facetedsearch >= 3.0.0, < 4.0.4
Fix: upgrade to 4.0.4
– prestashop ps_facetedsearch >= 3.0.0, < 4.0.4
Original advisory text
prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
### Impact

A PHP Object Injection vulnerability affects the PrestaShop module `ps_facetedsearch`.

The module rebuilds the selected search filters from the request URL. The value of a slider filter (**price** or **weight**) is taken from the URL without sufficient validation, then stored in an internal filter-block cache where it is serialized and later read back with a raw native `unserialize()`.
By crafting that value, an attacker can smuggle a malicious serialized PHP object into the cache. When it is deserialized, a gadget chain writes an arbitrary PHP file inside the module directory, which is then used as a webshell to run commands on the server.

### Who is impacted

Any shop using a vulnerable version of `ps_facetedsearch` that displays a filter template containing a slider filter (price or weight). Exploitation is remote and **unauthenticated**, a single crafted front-office request is enough, and leads to remote code
execution and full compromise of the shop and its server.

**Affected versions:** `3.0.0` through `4.0.3` (all versions since 3.0.0, including the latest release).


### Patches

Upgrade the `ps_facetedsearch` module to the patched version. Upgrading the module is the best action that removes the vulnerability.

Otherwise, you can apply the fix manually in the file `src/Filters/Block.php`:

In the `getFromCache()` method, replace the native `unserialize()` call:

```php
// Before
if (!empty($row)) {
return unserialize(current($row));
}

// After
if (!empty($row)) {
return \Tools::unSerialize(current($row));
}
```

### Until the module is upgraded:

- Remove price and weight slider filters from the filter templates that are exposed on the
front office.
- Clear the faceted-search filter cache, and audit the `modules/ps_facetedsearch/` directory for
unexpected PHP files.
- Monitor search requests for PHP serialization patterns (`O:`, `;i:`, references to classes such
as `Monolog\…`) and block them at the WAF level.

### Resources

- Thank you to Frédéric Moreau (Antadis) and Gilles Caudal (Datalinx) for reporting this vulnerability.
Severity
10.0 Critical
CVSS 3.1: 10.0 (GHSA)
Exploitation
EPSS <1%
Type
CWE-74Injection
Timeline
Published10 Jul 2026
Updated27 Sep 2026
First seen10 Jul 2026
Sources
CVE-2026-54159 · MITRE
Track software like this
Free during beta