THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5vf4-452p-jjhf (medium) — Shopper: Negative discount values accepted and propagated through order calculation pipeline

[GHSA] GHSA-5vf4-452p-jjhf (medium) — Shopper: Negative discount values accepted and propagated through order calculation pipeline

medgithub_advisoriesPublished 2026-09-11

GHSA-5vf4-452p-jjhf Severity: medium CVE: CVE-2026-56831

Shopper: Negative discount values accepted and propagated through order calculation pipeline

## Summary

The Shopper Framework discount management functionality accepts negative discount values without server-side validation.

It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persist

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5vf4-452p-jjhf