While working on invoiceneko project, I discovered a critical vulnerability in the binarytorch/larecipe package. This is a Server-Side Template Injection (SSTI) issue that could allow attackers to execute arbitrary code, access sensitive environment variables, or escalate privileges on the server.
CVE Link
CVE Report
While working on invoiceneko project, I discovered a critical vulnerability in the binarytorch/larecipe package. This is a Server-Side Template Injection (SSTI) issue that could allow attackers to execute arbitrary code, access sensitive environment variables, or escalate privileges on the server.
CVE Link
CVE Report