@remotion/studio@4.0.392

APIs for interacting with the Remotion Studio

  • latest version

    4.0.507

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @remotion/studio package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Arbitrary Code Injection

    @remotion/studio is an APIs for interacting with the Remotion Studio

    Affected versions of this package are vulnerable to Arbitrary Code Injection through the process responsible for handling remote inputs. An attacker can execute arbitrary code by sending specially crafted requests over the network.

    How to fix Arbitrary Code Injection?

    Upgrade @remotion/studio to version 4.0.410 or higher.

    <4.0.410
    • H
    Write-what-where Condition

    @remotion/studio is an APIs for interacting with the Remotion Studio

    Affected versions of this package are vulnerable to Write-what-where Condition via the file write process. An attacker can overwrite or create arbitrary files by sending specially crafted input to the application.

    How to fix Write-what-where Condition?

    Upgrade @remotion/studio to version 4.0.410 or higher.

    <4.0.410