New Solidus releases to address security vulnerabilities

Jared Norman
7 Oct 2026 - 3 mins read

Today we're disclosing several security vulnerabilities affecting Solidus, its
admin, its frontends and solidus_auth_devise:
- GHSA-rw5f-4cm4-pc4m: Users with UserManagement permissions can assign themselves the admin role or change an admin's password
- GHSA-x943-j5hw-mr2w: Stored cross-site scripting in Solidus product descriptions
- GHSA-6p7r-vx57-9gw3: Missing authorization check on return item inventory units allows cancelling other customers' returns
- GHSA-qwqm-3jx5-rr8m: Checkout state skip via unvalidated state parameter
- GHSA-vgwx-9pm9-8qvj: Customers can attach another user's stored gateway payment profile to their own payment
- GHSA-g9c8-3mxq-rpgh: Stored cross-site scripting in Solidus admin customer purchased items
- GHSA-3cfg-886h-22vf: Unrestricted type assignment in admin payment methods controller
- GHSA-87gm-56c6-255g: Stored cross-site scripting in Solidus Frontend order details
- GHSA-mc6q-7qq6-ghg8: Password reset endpoints allow for account enumeration
- GHSA-mhwq-2v9w-r659: Storefront password reset endpoint allows for account enumeration
The first five affect Solidus itself and can be addressed by upgrading to Solidus 4.7.2 or 4.6.4.
The next two affect the new Solidus admin, solidus_admin. The cross-site
scripting vulnerability is fixed in solidus_admin
0.4.1,
a maintenance release that contains only this fix. The payment method type
vulnerability only affects stores running solidus_admin from the main
branch; the published 0.4.0 gem is not affected. If you track main, update to
the latest commit. The fix will be part of solidus_admin 0.5.0.
If you use Solidus Frontend, you should also upgrade solidus_frontend to
either 4.7.2
or 4.6.4,
depending on your Solidus version. Its order details render product
descriptions through a separate helper, so upgrading Solidus alone does not fix
them.
The last two are the same vulnerability in the password reset endpoints, and
only matter to stores that rely on Devise's paranoid mode to prevent account
enumeration. The admin endpoint, and the storefront endpoint for stores using
Solidus Frontend, are fixed in solidus_auth_devise
2.6.1.
If you use Solidus Storefront, be aware that because it generates code into
your application, upgrading your gems is not enough to resolve this
vulnerability: you must update your application's own code as described in
the advisory.
Each advisory includes a workaround for stores that cannot upgrade right away.
You can read about these vulnerabilities on the Solidus mailing list.
If you have any questions about how to secure your site please stop by our Slack http://slack.solidus.io/.
Have a nice day!