Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv7x-xhv2-p5v2

Опубликовано: 14 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

LaRecipe is vulnerable to Server-Side Template Injection attacks

Impact

Attackers could:

  1. Execute arbitrary commands on the server
  2. Access sensitive environment variables
  3. Escalate access depending on server configuration

A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.

Patches

Users are strongly advised to upgrade to version v2.8.1 or later.

Credit

We would like to thank Roman Ananev for responsibly identifying and reporting this vulnerability.

Пакеты

Наименование

binarytorch/larecipe

composer
Затронутые версииВерсия исправления

< 2.8.1

2.8.1

EPSS

Процентиль: 95%
0.16492
Средний

10 Critical

CVSS3

Дефекты

CWE-1336

Связанные уязвимости

CVSS3: 10
nvd
19 дней назад

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration. Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.

EPSS

Процентиль: 95%
0.16492
Средний

10 Critical

CVSS3

Дефекты

CWE-1336