Attackers could: 1. Execute arbitrary commands on the server 2. Access sensitive environment variables 3. Escalate access depending on server configuration
A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.
Users are strongly advised to upgrade to version v2.8.1 or later.
We would like to thank Roman Ananev for responsibly identifying and reporting this vulnerability.
{ "github_reviewed": true, "severity": "CRITICAL", "github_reviewed_at": "2025-07-14T21:22:01Z", "cwe_ids": [ "CWE-1336" ], "nvd_published_at": "2025-07-14T23:15:24Z" }