Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-jv7x-xhv2-p5v2: LaRecipe is vulnerable to Server-Side Template Injection attacks

Impact

Attackers could:

  1. Execute arbitrary commands on the server
  2. Access sensitive environment variables
  3. Escalate access depending on server configuration

A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.

Patches

Users are strongly advised to upgrade to version v2.8.1 or later.

ghsa
#vulnerability#git#rce
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-53833

LaRecipe is vulnerable to Server-Side Template Injection attacks

Critical severity GitHub Reviewed Published Jul 14, 2025 in saleem-hadad/larecipe • Updated Jul 14, 2025

Package

composer binarytorch/larecipe (Composer)

Affected versions

< 2.8.1

Impact

Attackers could:

  1. Execute arbitrary commands on the server
  2. Access sensitive environment variables
  3. Escalate access depending on server configuration

A critical vulnerability was discovered in LaRecipe that allows an attacker to perform Server-Side Template Injection (SSTI), potentially leading to Remote Code Execution (RCE) in vulnerable configurations.

Patches

Users are strongly advised to upgrade to version v2.8.1 or later.

References

  • GHSA-jv7x-xhv2-p5v2
  • saleem-hadad/larecipe#390
  • saleem-hadad/larecipe@c1d0d56

Published to the GitHub Advisory Database

Jul 14, 2025

Last updated

Jul 14, 2025

ghsa: Latest News

GHSA-32mf-57h2-64x9: XWiki Rendering is vulnerable to RCE attacks when processing nested macros