VDB
Sign up
CRITICAL9.8

GHSA-9qgm-w87q-hx89

Unrestricted Upload of File with Dangerous Type in Strapi

Details

An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi
Introduced in: 0

No fixed version published yet for strapi (npm). Pin to a known-safe version or switch to an alternative.

References