Skip to content
#

session-reaper

Here is 1 public repository matching this topic...

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.

  • Updated Nov 9, 2025
  • PHP

Improve this page

Add a description, image, and links to the session-reaper topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the session-reaper topic, visit your repo's landing page and select "manage topics."

Learn more