@remotion/studio-server is vulnerable to Improper Access Control
41
Medium Risk
Affected versions of this package expose server endpoints (such as those handling /api/add-asset and filesystem explorer actions) with insufficient origin and input validation, which could be abused by a malicious web client to interact with the host filesystem without proper access control. The patched version introduces origin host checks, file path restrictions, and randomized API prefixes to better restrict access to these filesystem operations and reduce the risk of unauthorized filesystem interaction.
You are affected if you are using a version that falls within the vulnerable range.
@remotion/studio-server is vulnerable to Improper Access Control in versions 4.0.364 - 4.0.409.
Upgrade the @remotion/studio-server library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant