New Solidus releases to address security vulnerabilities

portrait of Jared Norman

Jared Norman

7 Oct 2026 - 3 mins read

Cover image of New Solidus releases to address security vulnerabilities post

Today we're disclosing several security vulnerabilities affecting Solidus, its admin, its frontends and solidus_auth_devise:

The first five affect Solidus itself and can be addressed by upgrading to Solidus 4.7.2 or 4.6.4.

The next two affect the new Solidus admin, solidus_admin. The cross-site scripting vulnerability is fixed in solidus_admin 0.4.1, a maintenance release that contains only this fix. The payment method type vulnerability only affects stores running solidus_admin from the main branch; the published 0.4.0 gem is not affected. If you track main, update to the latest commit. The fix will be part of solidus_admin 0.5.0.

If you use Solidus Frontend, you should also upgrade solidus_frontend to either 4.7.2 or 4.6.4, depending on your Solidus version. Its order details render product descriptions through a separate helper, so upgrading Solidus alone does not fix them.

The last two are the same vulnerability in the password reset endpoints, and only matter to stores that rely on Devise's paranoid mode to prevent account enumeration. The admin endpoint, and the storefront endpoint for stores using Solidus Frontend, are fixed in solidus_auth_devise 2.6.1. If you use Solidus Storefront, be aware that because it generates code into your application, upgrading your gems is not enough to resolve this vulnerability: you must update your application's own code as described in the advisory.

Each advisory includes a workaround for stores that cannot upgrade right away.

You can read about these vulnerabilities on the Solidus mailing list.

If you have any questions about how to secure your site please stop by our Slack http://slack.solidus.io/.

Have a nice day!