SCA: security update for sylius/mollie-plugin (GHSA-rc52-c4hv-w89p)

high Tenable Self-Hosted Container Security Plugin ID 445532

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4,
and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-
controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced
Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim
order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
(CVE-2026-68500)

Solution

Update the sylius/mollie-plugin library and its related packages to version 2.2.8 or later.

See Also

https://github.com/advisories/GHSA-rc52-c4hv-w89p

Plugin Details

Severity: High

ID: 445532

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/1/2026

Updated: 8/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.74

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-68500

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/31/2026

Vulnerability Publication Date: 7/30/2026

Reference Information

CVE: CVE-2026-68500

cwe: CWE-639