Skip to content

medusa

v2.15.5 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

Published 2d API Development
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

commerce e-commerce ecommerce javascript medusa nodejs
+2 more
react typescript

Affected surfaces

auth rbac

Summary

AI summary

Broad release touches Chores, Bugs, https://github.com/shahednasser, and Highlights.

Changes in this release

Feature Medium

Adds admin MFA UI for managing authentication methods.

Adds admin MFA UI for managing authentication methods.

Source: llm_adapter@2026-06-01

Confidence: high

Feature Medium

Emits MFA lifecycle events for tracking authentication flows.

Emits MFA lifecycle events for tracking authentication flows.

Source: llm_adapter@2026-06-01

Confidence: high

Feature Medium

Adds email verification primitives for MFA.

Adds email verification primitives for MFA.

Source: llm_adapter@2026-06-01

Confidence: high

Feature Medium

Allows cancelling pending MFA setup.

Allows cancelling pending MFA setup.

Source: llm_adapter@2026-06-01

Confidence: high

Bugfix Medium

Corrects order list status badge colors when view_configurations is enabled.

Corrects order list status badge colors when view_configurations is enabled.

Source: llm_adapter@2026-06-01

Confidence: high

Bugfix Medium

Avoids refunding captures from separate completeCartWorkflow executions.

Avoids refunding captures from separate completeCartWorkflow executions.

Source: llm_adapter@2026-06-01

Confidence: low

Bugfix Medium

Respects allow_backorder when calculating pickup inventory availability.

Respects allow_backorder when calculating pickup inventory availability.

Source: llm_adapter@2026-06-01

Confidence: low

Bugfix Medium

Uses hasPermission util for user role permission validation in core‑flows.

Uses hasPermission util for user role permission validation in core‑flows.

Source: llm_adapter@2026-06-01

Confidence: low

Bugfix Medium

Aligns user permission checks with hasPermission util across core‑flows and medusa.

Aligns user permission checks with hasPermission util across core‑flows and medusa.

Source: llm_adapter@2026-06-01

Confidence: low

Full changelog

Highlights

Email Verification for Multi-Factor Authentication

Medusa now supports email verification primitives for multi-factor authentication (MFA). The admin dashboard includes a complete MFA UI that allows users to set up and manage their authentication methods. MFA lifecycle events are now emitted for tracking authentication flows.

#15496
#15493
#15495

Features

Bugs

  • fix(core-flows): avoid refunding captures made in separate completeCartWorkflow executions by @NicolasGorga in #15527
  • fix(utils): add mfa to inline snapshot test assertion by @NicolasGorga in #15518
  • fix(core-flows): respect allow_backorder when calculating pickup inventory availability by @marlinjai in #15440
  • Allow cancelling pending MFA setup by @christiananese in #15475
  • fix(dashboard): order list status badges show correct colors when view_configurations is enabled by @shiminshen in #15430
  • fix(core-flows): use hasPermission util to perform checks in validateUserRolePermissionsStep by @NicolasGorga in #15470
  • fix(core-flows,medusa): align validate user permissions check with hasPermission util by @NicolasGorga in #15465

Documentation

Chores

Full Changelog: v2.15.3...v2.15.5

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track medusa

Get notified when new releases ship.

Sign up free

About medusa

The world's most flexible commerce platform.

All releases →

Related context

Earlier breaking changes

  • v2.15.0 Product and variant width/length/height/weight properties aligned to float type

Beta — feedback welcome: [email protected]