Defense-in-depth patch set for StyleSmuggler (https://sansec.io/research/stylesmuggler — unauthenticated Magento/Adobe Commerce RCE, disclosed 2026-09-05, no vendor patch yet).
Adaptation of https://gist.github.com/rhoerr/291d29ef3bd201c96757cf262d92bdaf for
Mage-OS package names, split per package with package-root-relative paths so they drop
straight into vaimo/composer-patches, plus CLI-only guards on the two DI scanner sinks
the original set does not cover (ClassesScanner::includeClass(),
XmlInterceptorScanner::_handleControllerClassName() — same approach as