CVE-2019-19609

HIGH7.2EPSS 81.1%

Command Injection in strapi

Published: 12/10/2021Modified: 12/29/2025

Description

Versions of `strapi` before 3.0.0-beta.17.8 are vulnerable to Command Injection. The package fails to sanitize plugin names in the `/admin/plugins/install/` route. This may allow an authenticated attacker with admin privileges to run arbitrary commands in the server. ## Recommendation Upgrade to version 3.0.0-beta.17.8 or later

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (7)