Detects Magento / Adobe Commerce instances where the REST API ServiceInputProcessor accepts nested objects in guest checkout endpoints, enabling unauthenticated session takeover and remote code execution via DI traversal + session poisoning. Affects all versions through 2.4.7-p7, 2.4.8-p2, and 2.4.9-alpha2.
Is your app exploitable through CVE-2025-54236?
Scan your domain free