@strapi/strapi is vulnerable to URL Redirection to Untrusted Site ('Open Redirect')
80
High Risk
Affected versions of the @strapi/strapi library are vulnerable to open redirect. @strapi/strapi accepts user-controlled input that specifies a link to an external site and uses that link in a redirect. This vulnerability simplifies phishing attacks. The plugin configuration can be customized by the user and is not properly validated.
You are affected if you are using a version that falls within the vulnerable range.
@strapi/strapi is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 4.0.0 - 4.24.1.
Upgrade the @strapi/strapi library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant