VDB
Sign up
MEDIUM6.1

GHSA-xrjf-phvv-r4vr

Command injection in strapi

Quick fix

GHSA-xrjf-phvv-r4vr — strapi: upgrade to the fixed version with the command below.

npm install strapi@4.1.0

Details

When creating a strapi app using npxcreate-strapi-app, we can inject arbitrary commands through the template cli argument as per the code in this particular [link](https://github.com/strapi/strapi/blob/master/packages/generators/app/lib/utils/fetch-npm-template.js#L13), this happens due to improper sanitization of user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi
Introduced in: 0Fixed in: 4.1.0
Fixnpm install strapi@4.1.0

References