algolia/algoliasearch-magento-2
Algolia Search integration for Magento 2 - compatible with versions from 2.3.x to 2.4.x
Activity
- Latest release
- 1w ago
- Total releases
- 120
- Cadence
- ~17 days
- Last 12 months
- 17
Reach
- Stars
- 191
Details
- License
- MIT
- First release
- Aug 11, 2016
| Version | Released | |
|---|---|---|
3.19.1
patch
| ||
3.18.2
patch
| ||
3.19.0
minor
| ||
3.19.0-beta.1
pre
| ||
3.18.1
patch
| ||
3.17.4
patch
| ||
3.18.0
minor
| ||
3.17.3
patch
| ||
3.16.3
patch
| ||
3.18.0-beta.1
pre
| ||
3.16.2
patch
| ||
3.17.2
patch
| ||
3.17.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.17.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.17.0-beta.2
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.16.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.3
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.2
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.17.0-beta.1
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.16.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.16.0-beta.2
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.5
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.16.0-beta.1
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.0-beta.2
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.8
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.7
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.4
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.15.0-beta.1
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.3
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.6
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.2
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.0-beta.2
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.5
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.4
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.3
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.14.0-beta.1
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.2
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.13.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.12.1
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.12.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.11.1-beta
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.11.0
minor
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.10.6
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.11.0-beta
pre
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev | ||
3.10.5
patch
1 CVE
GHSA-595p-g7xc-c333
Jan 14, 2026
Algolia Search & Discovery for Magento 2 Has Untrusted Data Handling
Medium
Network
Low
None
None
ImpactVersions of the Algolia Search & Discovery extension for Magento 2 prior to 3.17.2 and 3.16.2 contain a vulnerability where data read from the database was treated as a trusted source during job execution. If an attacker is able to modify records used by the extension’s indexing queue, this could result in arbitrary PHP code execution when the affected job is processed. Exploitation requires the ability to write malicious data to the Magento database and for the indexing queue to be enabled. PatchesThis vulnerability has been fixed in the following versions:
Merchants should upgrade to a supported patched version immediately. Versions outside the supported maintenance window do not receive security updates and remain vulnerable. WorkaroundsUpgrading to a patched version is the only recommended remediation. If an immediate upgrade is not possible, the following temporary risk mitigations may reduce exposure:
These mitigations are provided as guidance only and do not replace upgrading to a patched version. ReferencesAffected versions
3.17.0
3.17.0-beta.1
3.17.0-beta.2
3.17.1
0.8.2
0.8.3
0.8.4
0.9.0
0.9.1
1.0.0
1.0.1
1.0.10
+ 96 more Show less
1.0.3
1.0.4
1.0.5
1.0.6
1.0.8
1.0.9
1.1.0
1.10.0
1.11.0
1.11.1
1.11.2
1.11.3
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.9.0
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
3.0.0
3.0.1
3.0.2
3.1.0
3.10.0
3.10.1
3.10.2
3.10.3
3.10.4
3.10.5
3.10.6
3.11.0
3.11.0-beta
3.11.1-beta
3.12.0
3.12.1
3.13.0
3.13.1
3.13.2
3.13.3
3.13.4
3.13.5
3.13.6
3.13.7
3.13.8
3.14.0
3.14.0-beta.1
3.14.0-beta.2
3.14.1
3.14.2
3.14.3
3.14.4
3.14.5
3.15.0
3.15.0-beta.1
3.15.0-beta.2
3.15.1
3.15.2
3.15.3
3.16.0
3.16.0-beta.1
3.16.0-beta.2
3.16.1
3.2.0
3.3.0
3.3.1
3.4.0
3.6.0
3.6.1
3.7.0
3.7.0-p1
3.7.0-p2
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.16.2
3.17.2
References Updated Feb 03, 2026 · Source: OSV.dev |