VDB
Sign up
HIGH7.2

GHSA-9p2w-rmx4-9mw7

Command Injection in strapi

Quick fix

GHSA-9p2w-rmx4-9mw7 — strapi: upgrade to the fixed version with the command below.

npm install strapi@3.0.0-beta.17.8

Details

Versions of `strapi` before 3.0.0-beta.17.8 are vulnerable to Command Injection. The package fails to sanitize plugin names in the `/admin/plugins/install/` route. This may allow an authenticated attacker with admin privileges to run arbitrary commands in the server.

## Recommendation

Upgrade to version 3.0.0-beta.17.8 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi
Introduced in: 0Fixed in: 3.0.0-beta.17.8
Fixnpm install strapi@3.0.0-beta.17.8

References