GHSA-49vv-6q7q-w5cf

Suggest an improvement
Source
https://github.com/advisories/GHSA-49vv-6q7q-w5cf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-49vv-6q7q-w5cf/GHSA-49vv-6q7q-w5cf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-49vv-6q7q-w5cf
Withdrawn
2025-12-29T15:34:37Z
Published
2021-12-10T17:22:12Z
Modified
2026-09-10T03:49:16Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Duplicate Advisory: OS Command Injection in Strapi
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9p2w-rmx4-9mw7. This link is maintained to preserve external references.

Original Description

The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-07-27T15:24:09Z",
    "nvd_published_at":  "2019-12-05T20:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / strapi

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.0-beta.17.8

Database specific

last_known_affected_version_range
"<= 3.0.0-beta.17.7"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-49vv-6q7q-w5cf/GHSA-49vv-6q7q-w5cf.json"