THREAT OPS › Threat News › [GHSA] GHSA-5vf4-452p-jjhf (medium) — Shopper: Negative discount values accepted and propagated through order calculation pipeline
[GHSA] GHSA-5vf4-452p-jjhf (medium) — Shopper: Negative discount values accepted and propagated through order calculation pipeline
GHSA-5vf4-452p-jjhf Severity: medium CVE: CVE-2026-56831
Shopper: Negative discount values accepted and propagated through order calculation pipeline
## Summary
The Shopper Framework discount management functionality accepts negative discount values without server-side validation.
It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persist
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-56831cve
Original source: https://github.com/advisories/GHSA-5vf4-452p-jjhf