mediumCVSS 5.9Vulnerability

GHSA-9rh9-hf3w-9fgg

## Impact `CreateOrderFromCartAction::execute` previously created the `Order` row before checking and incrementing the discount's `total_use` counter. Under concurrent checkout pressure (Black Friday, flash sale, viral coupon), the global `usage_limit` was silently exceeded: orders were committed with the discount fully applied to `price_amount` while the counter blocked at `usage_limit`. The merchant had no signal that an over-redemption had occurred. A second related bug: `usage_limit_per_user` was effectively a no-op because the counter it relied on (`DiscountDetail.total_use`) was never incremented anywhere in the codebase. The per-user check therefore always saw `0` uses and validation passed regardless of how many times the same customer had previously redeemed the coupon. For `eligibility = Everyone` the per-user limit could not fire at all because the underlying `DiscountDetail` row only exists for `eligibility = Customers`. Direct financial loss: each over-redemption is a discount the merchant did not intend to grant. ## Patches Fixed in `v2.8.0`. `CreateOrderFromCartAction` now: - Reserves the discount slot atomically before the order row is created, inside the same `DB::transaction` with `lockForUpdate` and a compare-and-swap on `total_use`. - Throws `DiscountLimitReachedException::global` and rolls back the transaction when the global limit was exhausted between cart validation and commit. No order is committed. - Throws `DiscountLimitReachedException::perUser` and rolls back when the discount is restricted to one use per customer and the customer has already redeemed it. - Snapshots `discount_id`, `discount_code`, `discount_type`, `discount_value_at_apply` and `discount_currency_code` onto the `orders` table for resilience against later discount edits or deletions. `DiscountValidator` was updated to perform the same Order-based per-user check at cart-apply time so the rejection is surfaced before checkout. Upgrade via: `composer require shopper

Properties

ghsa_id
GHSA-9rh9-hf3w-9fgg
severity
medium
summary
shopper/framework: Race condition on Discount.usage_limit allows silent over-redemption
cvss_score
5.9
cve_id
GHSA-9rh9-hf3w-9fgg
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-05-18T16:37:20Z
source_url
https://github.com/advisories/GHSA-9rh9-hf3w-9fgg
ghsa_updated
2026-05-18T16:37:21Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/shopper/cart

AFFECTS (1)

[Software]composer/shopper/cart

HAS_WEAKNESS (1)

[Weakness]Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9rh9-hf3w-9fgg (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal