@strapi/upload@0.0.0-experimental.acf5b8e2415961024d399288b1e1fba8a2ab5a9a

Makes it easy to upload images and files to your Strapi Application.

  • latest version

    5.52.1

  • latest non vulnerable version

  • first published

    2 years ago

  • latest version published

    1 days ago

  • Direct Vulnerabilities

    Known vulnerabilities in the @strapi/upload package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Upload

    @strapi/upload is a Makes it easy to upload images and files to your Strapi Application.

    Affected versions of this package are vulnerable to Arbitrary File Upload via the Content API uploadFiles and replaceFile handlers, which bypass administrator-configured MIME type restrictions. An attacker can upload files with disallowed types, such as HTML or SVG, by exploiting insufficient enforcement of security checks. This can lead to the execution of malicious scripts in the admin origin if an administrator opens the uploaded file, potentially resulting in session hijacking and unauthorized administrative actions.

    How to fix Arbitrary File Upload?

    Upgrade @strapi/upload to version 5.33.3 or higher.

    <5.33.3