CVE-2025-69871 | MedusaJS Medusa up to 2.12.2 Promotion registerUsage race condition
A vulnerability categorized as problematic has been discovered in MedusaJS Medusa up to 2.12.2. This affects the function registerUsage of the component Promotion Module. Such manipulation leads to race condition.
This vulnerability is traded as CVE-2025-69871. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.