Server side template injection In binarytorch/larecipe

Description

LaRecipe is vulnerable to Server-Side Template Injection attacks

Impact

Attackers could:

    Execute arbitrary commands on the server

    Access sensitive environment variables

    Escalate access depending on server configuration

A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.

Patches

Users are strongly advised to upgrade to version v2.8.1 or later.

Credit

We would like to thank Roman Ananev for responsibly identifying and reporting this vulnerability.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions