GHSA-97rh-rhh2-7vjv: Code Injection
Impact A crafted request to the public first-register operation can be used to perform a RCE exploit.
You are affected if:
- You use local auth strategy and your application remains without an initial user created
Patches
In the patched version data submission to create first user is properly sanitized.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
Payload packagesto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34