Skip to content

Command Injection in strapi

high severity Published Sep 4, 2020 • Updated Oct 4, 2021

Package

npm strapi (npm)

Affected versions

<= 3.0.0-beta.17.7

Patched versions

3.0.0-beta.17.8

Description

Versions of strapi before 3.0.0-beta.17.8 are vulnerable to Command Injection. The package fails to sanitize plugin names in the /admin/plugins/install/ route. This may allow an authenticated attacker with admin privileges to run arbitrary commands in the server.

Recommendation

Upgrade to version 3.0.0-beta.17.8 or later

References

GHSA ID

GHSA-9p2w-rmx4-9mw7