MEDIUM6.1
GHSA-xrjf-phvv-r4vr
Command injection in strapi
Quick fix
GHSA-xrjf-phvv-r4vr — strapi: upgrade to the fixed version with the command below.
npm install strapi@4.1.0Details
When creating a strapi app using npxcreate-strapi-app, we can inject arbitrary commands through the template cli argument as per the code in this particular [link](https://github.com/strapi/strapi/blob/master/packages/generators/app/lib/utils/fetch-npm-template.js#L13), this happens due to improper sanitization of user input.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0764[ADVISORY]
- https://github.com/strapi/strapi/issues/12879[WEB]
- https://github.com/strapi/strapi/commit/2a3f5e988be6a2c7dae5ac22b9e86d579b462f4c[WEB]
- https://github.com/strapi/strapi[PACKAGE]
- https://github.com/strapi/strapi/blob/master/packages/generators/app/lib/utils/fetch-npm-template.js#L13[WEB]
- https://huntr.dev/bounties/001d1c29-805a-4035-93bb-71a0e81da3e5[WEB]
- https://www.github.com/strapi/strapi/commit/2a3f5e988be6a2c7dae5ac22b9e86d579b462f4c[WEB]