@strapi/upload@0.0.0-experimental.334ab1f7fd16dbb5db683b1349922bbfa36bedea

Makes it easy to upload images and files to your Strapi Application.

  • latest version

    5.47.0

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    4 days ago

  • Direct Vulnerabilities

    Known vulnerabilities in the @strapi/upload package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Upload

    @strapi/upload is a Makes it easy to upload images and files to your Strapi Application.

    Affected versions of this package are vulnerable to Arbitrary File Upload via the Content API uploadFiles and replaceFile handlers, which bypass administrator-configured MIME type restrictions. An attacker can upload files with disallowed types, such as HTML or SVG, by exploiting insufficient enforcement of security checks. This can lead to the execution of malicious scripts in the admin origin if an administrator opens the uploaded file, potentially resulting in session hijacking and unauthorized administrative actions.

    How to fix Arbitrary File Upload?

    Upgrade @strapi/upload to version 5.33.3 or higher.

    <5.33.3