@strapi/core is vulnerable to Protection Mechanism Failure
45
Medium Risk
Affected versions of this package could allow inconsistent or overly permissive MIME validation during file uploads, causing the system to trust incorrect declared or stored content types, mishandle allow/deny rules, and persist misleading metadata such as application/octet-stream instead of the validated type. An attacker might exploit this by disguising a malicious file as an allowed format, abusing weak validation order or allow-list enforcement to upload content that is later served with an unsafe or misleading Content-Type, potentially increasing the risk of dangerous file delivery, content spoofing, or bypass of upload restrictions.
You are affected if you are using a version that falls within the vulnerable range.
@strapi/core is vulnerable to Protection Mechanism Failure in versions 3.0.0 - 5.38.1.
Upgrade the @strapi/core library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant