CRITICAL9.8
GHSA-9qgm-w87q-hx89
Unrestricted Upload of File with Dangerous Type in Strapi
Details
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/strapi
Introduced in:
0No fixed version published yet for strapi (npm). Pin to a known-safe version or switch to an alternative.