---
id: CVE-2026-108690
title: >-
  mall4j through 4.0 contains an information disclosure vulnerability that
  allows authenticated customers to read other shoppers' cart items due to an
  operator precedence error in the getShopCartExpiryItems SQL filter
summary: >-
  mall4j through 4.0 contains an information disclosure vulnerability that
  allows authenticated customers to read other shoppers' cart items due to an
  operator precedence error in the getShopCartExpiryItems SQL filter. Attackers
  with any s…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-783
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T02:16:37.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108690'
references:
  - url: >-
      https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/mall4j/poc_shopcart_expiry_prodlist.py
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/ShopCartController.java#L162-L186
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/resources/mapper/BasketMapper.xml#L41-L48
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mall4j-through-4.0-operator-precedence-error-exposes-other-users-cart-items-via-p-shopcart-expiryprodlist
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-11T02:38:44.033Z'
---

## Overview

mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
