How to Secure Your Magento 2 Store Against APSB25-88 Vulnerability

How to Secure Your Magento 2 Store Against APSB25-88 Vulnerability

Magento 2 store owners, it’s time to take quick action. Adobe recently released an important security update fixing a critical issue that could allow unauthorized code execution. If your store hasn’t been patched yet, you should act immediately. After applying the patch, take one more important step - disable unused and risky file upload endpoints such as customer address file uploads and custom options file uploads.

Good news - Adobe’s official patch is out

Good news: Adobe managed to complete the issue on time and rolled out an emergency patch that completely fixes the vulnerability.

Now it’s your turn - apply the patch and protect your store. Don’t delay, act now.

Follow Adobe’s official instructions here: Adobe Patch Instructions.

How to apply the patch

Download the patch VULN-32437-2-4-X and run the following commands from your Magento 2 root directory:

curl -LO https://repo.magento.com/patch/VULN-32437-2-4-X-patch.zip
unzip VULN-32437-2-4-X-patch.zip
patch -p1 < VULN-32437_2.4.X.patch && \
php -d memory_limit=-1 bin/magento cache:clean

After running these commands, you should see a change in vendor/magento/framework/Webapi/ServiceInputProcessor.php similar to this:

diff --git a/vendor/magento/framework/Webapi/ServiceInputProcessor.php b/vendor/magento/framework/Webapi/ServiceInputProcessor.php
index ba58dc2bc7acf..06919af36d2eb 100644
--- a/vendor/magento/framework/Webapi/ServiceInputProcessor.php
+++ b/vendor/magento/framework/Webapi/ServiceInputProcessor.php
@@ -246,6 +246,13 @@ private function getConstructorData(string $className, array $data): array
             if (isset($data[$parameter->getName()])) {
                 $parameterType = $this->typeProcessor->getParamType($parameter);

+                // Allow only simple types or Api Data Objects
+                if (!($this->typeProcessor->isTypeSimple($parameterType)
+                    || preg_match('~\\\\?\w+\\\\\w+\\\\Api\\\\Data\\\\~', $parameterType) === 1
+                )) {
+                    continue;
+                }
+
                 try {
                     $res[$parameter->getName()] = $this->convertValue($data[$parameter->getName()], $parameterType);
                 } catch (\ReflectionException $e) {

Integration of the Patch in Later Versions

As of October 14, Adobe officially included the fix in the APSB25-94 release. You can verify this in the Adobe Security Bulletin.

Stores running the following versions are already protected:

  • Magento 2.4.6-p13
  • Magento 2.4.7-p8
  • Magento 2.4.8-p3

If you are on one of these releases, you’re all set - but double-check your update status to be sure you’re protected from APSB25-94 and related vulnerabilities.

Now, secure your store even further

After patching, take the next proactive step: lock down the two most commonly-abused upload endpoints in Magento 2. These are two separate entry points, each requiring its own fix - one covers custom options file uploads (used when a product lets customers upload a file, e.g. a logo to engrave), the other covers the customer address file upload attribute. Both are important and address different endpoints - we recommend installing both.

Protect custom options uploads: PolyShell Protection module

Module: aregowe/magento2-module-polyshell-protection
Purpose: Defense-in-depth against the PolyShell unrestricted file upload vulnerability (APSB25-94) affecting Magento Open Source and Adobe Commerce up to 2.4.9-alpha2 - most commonly exploited via custom options file uploads on product pages. It layers eight separate protections - request path blocking, controller-level upload prevention, polyglot file detection, and framework-level image hardening - across nine plugins covering REST API upload endpoints, media serving, and image processing.

Install via Composer (recommended if your host supports it):

composer require aregowe/magento2-module-polyshell-protection
bin/magento module:enable Aregowe_PolyShellProtection
bin/magento setup:upgrade
bin/magento cache:flush

Install manually at app/code (no Composer access needed): download the repository as a ZIP from GitHub, then:

mkdir -p app/code/Aregowe/PolyShellProtection
# extract the downloaded ZIP contents into that folder, so that
# app/code/Aregowe/PolyShellProtection/registration.php exists
bin/magento module:enable Aregowe_PolyShellProtection
bin/magento setup:upgrade
bin/magento cache:flush

Once enabled, go to Stores > Configuration > PolyShell Protection to review the allowed/blocked file extensions - no code changes needed to tune it further.

Protect customer address uploads: disable the upload endpoint

Module: basecom/magento2-disable-customer-address-file-upload
Purpose: Disables the customer address file upload endpoint specifically - a different upload path from custom options, and one most stores never actually use, so disabling it removes the risk entirely rather than merely filtering it.

Install via Composer:

composer require basecom/magento2-disable-customer-address-file-upload
bin/magento module:enable Basecom_DisableCustomerAddressFileUpload
bin/magento setup:upgrade
bin/magento cache:clean

Install manually at app/code (no Composer access needed): download the repository as a ZIP from GitHub, then:

mkdir -p app/code/Basecom/DisableCustomerAddressFileUpload
# extract the downloaded ZIP contents into that folder, so that
# app/code/Basecom/DisableCustomerAddressFileUpload/registration.php exists
bin/magento module:enable Basecom_DisableCustomerAddressFileUpload
bin/magento setup:upgrade
bin/magento cache:clean

Once enabled, any file upload attempts via the customer address form or API will be blocked, closing a potential attack surface that many stores overlook. No further configuration is required.

Final thoughts

Security is an ongoing process. Applying Adobe’s latest patch keeps your Magento 2 core secure. The two modules above do different things: one prevents malicious uploads via custom options, the other closes the separate customer address upload endpoint. Neither replaces the other - install both, alongside the core patch, to achieve layered protection and peace of mind.