CVE-2026-91154 Ecommerce Template 关键功能缺失认证漏洞
影响未授权攻击者可远程强制清空商店产品缓存,导致服务性能下降甚至拒绝服务
该漏洞存在于 MarcosCamara01 Ecommerce Template 的 Server Action 中。revalidateProducts 函数缺少会话与角色校验,任何未认证用户均可调用。由于该函数被编译进公开的 /_next/static 代码块且未被中间件拦截,攻击者可提取其 Action ID 直接触发缓存失效。
影响范围
受影响版本为 commit ec97209 之前的 MarcosCamara01 Ecommerce Template,具体版本号暂无公开信息。
漏洞详情
漏洞类型为关键功能缺少身份认证(CWE-306)。文件顶部声明 "use server",使所有导出函数被编译为可通过 POST 调用的 Server Action。revalidateProducts 调用 updateTag("products") 时未做任何会话或角色检查,而同文件中的只读操作因构造方式安全。两个管理端客户端组件导入该函数,导致其 Action ID 被打包进公开静态资源,管理员中间件 proxy.ts 未对其做访问控制。
利用条件与风险
利用无需认证,攻击者只需从公开 bundle 中提取 Action ID 即可反复调用。在启用 cacheComponents 时,整个店面(首页、分类、产品页、搜索)均依赖带 products 标签的缓存,反复触发会导致缓存持续失效,造成性能骤降甚至拒绝服务。
修复建议
官方修复方案为升级至 commit ec97209 或之后版本,在 revalidateProducts 中加入会话与角色校验。临时缓解措施为在中间件或网关层限制对该 Server Action 的未认证调用,暂无其他公开信息。
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares “use server” at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag(“products”) with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application’s admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from “use cache” entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor’s request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.