Server side template injection In binarytorch/larecipe
Description
LaRecipe is vulnerable to Server-Side Template Injection attacks
Impact
Attackers could:
Execute arbitrary commands on the server
Access sensitive environment variables
Escalate access depending on server configuration
A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.
Patches
Users are strongly advised to upgrade to version v2.8.1 or later.
Credit
We would like to thank Roman Ananev for responsibly identifying and reporting this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.8.1 |
Aliases
References