CVE-2025-54236 · SessionReaper

Is your store exposed to SessionReaper?

Run a free, passive check — no signup, no impact on your store.

No signup Passive & safe Results in seconds
SessionReaper CVE-2025-54236 CosmicSting CVE-2024-34102 TrojanOrders CVE-2022-24086 Magecart skimmers

SessionReaper (CVE-2025-54236) is a critical Magento 2 and Adobe Commerce vulnerability disclosed in 2025 that can lead to unauthenticated takeover through unsafe session handling. MageArgus checks your store’s exposure for free in under 10 seconds by fingerprinting your version and comparing it to the patched releases.

What is SessionReaper (CVE-2025-54236)?

SessionReaper is the community name for a critical vulnerability in the Magento 2 and Adobe Commerce session/REST layer. Like the CVEs before it, it became a mass-exploitation target within days of disclosure because so many stores run unpatched, internet-facing Magento.

The danger with this class of bug is that it does not need credentials. An attacker who can reach your storefront can attempt the exploit directly, which is why exposure is essentially a function of which version and patch level you are running — exactly what MageArgus fingerprints from the outside.

How MageArgus checks your exposure

1

Fingerprint

We detect your Magento / Adobe Commerce edition and version from public signals — no login required.

2

Map to the CVE

Your version is compared against the patched releases and the official security patch for CVE-2025-54236.

3

Get the fix

You get a clear verdict plus the exact upgrade or hotfix command to close the gap.

How to fix SessionReaper

Apply Adobe’s official security patch for CVE-2025-54236 or upgrade to a fixed release line. After patching, re-run the scan to confirm the version moved and the finding clears.

Frequently asked questions

How do I know if I’m vulnerable to SessionReaper?
Enter your store URL above and run the free scan. MageArgus fingerprints your version and tells you immediately whether it falls in the vulnerable range for CVE-2025-54236, plus the patch to apply.
Is the SessionReaper check safe to run?
Yes. The free scan is passive — it only reads publicly available signals from your storefront. It does not attempt the exploit or send any payload to your store.
My version looks patched — am I definitely safe?
A remote scan reads the version your store advertises. To confirm the patch is genuinely applied on disk (and rule out a partially-applied fix), install the MageArgus module, which greps the fixed files directly.

Check your SessionReaper exposure now

Free, passive, no signup. See your result in seconds.

Scan my store free