@strapi/upload@0.0.0-experimental.a4df7ad5ff6a4366442059f7c067a0424ba1e2f9

Makes it easy to upload images and files to your Strapi Application.

  • latest version

    5.52.1

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    5 days ago

  • Direct Vulnerabilities

    Known vulnerabilities in the @strapi/upload package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Upload

    @strapi/upload is a Makes it easy to upload images and files to your Strapi Application.

    Affected versions of this package are vulnerable to Arbitrary File Upload via the Content API uploadFiles and replaceFile handlers, which bypass administrator-configured MIME type restrictions. An attacker can upload files with disallowed types, such as HTML or SVG, by exploiting insufficient enforcement of security checks. This can lead to the execution of malicious scripts in the admin origin if an administrator opens the uploaded file, potentially resulting in session hijacking and unauthorized administrative actions.

    How to fix Arbitrary File Upload?

    Upgrade @strapi/upload to version 5.33.3 or higher.

    <5.33.3