CVE-2026-90896 | MarcosCamara01 Ecommerce Template Checkout Session Lookup route.ts stripe.checkout.sessions.retrieve session_id missing authentication (91e273c)
A vulnerability was found in MarcosCamara01 Ecommerce Template. It has been declared as problematic. This vulnerability affects the function stripe.checkout.sessions.retrieve of the file src/app/api/stripe/checkout_sessions/route.ts of the component Checkout Session Lookup Handler. Executing a manipulation of the argument session_id can lead to missing authentication.
This vulnerability is registered as CVE-2026-90896. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More