LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical severity
GitHub Reviewed
Published
Jul 14, 2025
in
saleem-hadad/larecipe
•
Updated Jul 15, 2025
Description
Published to the GitHub Advisory Database
Jul 14, 2025
Reviewed
Jul 14, 2025
Published by the National Vulnerability Database
Jul 14, 2025
Last updated
Jul 15, 2025
Impact
Attackers could:
A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.
Patches
Users are strongly advised to upgrade to version v2.8.1 or later.
References