Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service
Description
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action revalidateProducts (src/app/actions.ts), in Ecommerce Template before commit ec97209, which allows a remote, unauthenticated attacker to force immediate expiration of the entire storefront product cache. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only functions in the same file, which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the admin middleware (proxy.ts) does not gate, allowing any unauthenticated user to extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cache life. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every real visit to recompute the full catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Vulnerability type (CWE)
CWE-306: Missing Authentication for Critical Function
Affected versions
Ecommerce Template in all versions before commit ec97209. The vulnerable function was introduced in commit 4c7a666 (2026-01-18). The repository publishes no tags or releases and its package.json is pinned at 0.1.0, so there is no semantic version to reference; the affected range is therefore expressed by commit. The fix is contained in commit ec97209 (2026-09-08). Default status: unaffected.
Score (CVSS 4.0)
Medium (6.9)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Solution
Upgrade to a build that includes commit ec97209. The fix moves revalidateProducts out of the file-scoped "use server" module into a server-only module, and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped "use server" module; gate any cache-invalidation action behind a session or admin-role check, or remove the client-invocable export entirely.
Patch
Commit ec97209
Credits
- Robert Mihaila - finder
- Amirreza Fadaeizadeh Bidari - finder
- Darío Rivas Quero - analyst
- Secur0 CNA - coordinator
Discovery source: External
Official record: CVE-2026-91154