{"api_version":"v1","generated_at":"2026-10-10T03:10:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-marcoscamara01-ecommerce-template-f60426e9ec42","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Ecommerce Template","next_cursor":null,"observations":[{"affected":"Ecommerce Template: < ec97209","affected_versions_present":true,"cve_id":"CVE-2026-91154","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91154","fixed":"Update to a build including commit ec97209, which moves revalidateProducts out of the file-scoped \"use server\" module into a server-only module and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped \"use server\" module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely.","last_modified":"2026-09-28T17:52:40.759Z","patch_url":"https://github.com/MarcosCamara01/ecommerce-template/commit/ec97209e6c7663cba7b5164468d6946cbfe2f19a","primary_source":"","published":"2026-09-28T15:29:03.261Z"},{"affected":"Ecommerce Template: < 91e273c","affected_versions_present":true,"cve_id":"CVE-2026-90896","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90896","fixed":"Update to a build including commit 91e273c, which requires an authenticated session (401 otherwise) and verifies that checkoutSession.metadata.userId matches the authenticated user (403 otherwise) before returning the checkout session.","last_modified":"2026-09-15T19:17:02.930Z","patch_url":"https://github.com/MarcosCamara01/ecommerce-template/commit/91e273c69d976a3d205179e66e01fc399bfdd08b","primary_source":"","published":"2026-09-14T20:58:39.818Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"MarcosCamara01"}}
