CVE-2024-57177

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 10, 2025
CWE ID 74

Summary

CVE-2024-57177: A critical vulnerability has been identified in the perfood/couch-auth NPM package versions prior to 0.21.2. Hackers can exploit a host header injection flaw to execute a Server-Side Template Injection (SSTI) attack. By manipulating the host header in an email change confirmation request, they can run limited commands or gain access to sensitive server-side data. This vulnerability poses a significant threat to applications using the affected NPM package and necessitates an immediate update.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share