Skip to content
StripeGHSA-fv4g-gwpj-74gr

Vulnerability in stripe-cli >= 1.11.1

High7.5CVE-2024-45401 · Published Sep 5, 2024 · updated Sep 9, 2024

### Impact A vulnerability exists in stripe-cli versions 1.11.1 and higher where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability. ### Recommendation Upgrade to stripe-cli v1.21.3. ### Acknowledgements Thank you to [0xacb](https://hackerone.com/0xacb) and [bordiez](https://hackerone.com/bordiez) for reporting this vulnerability. ### For more information Email us at [security@stripe.com](mailto:security@stripe.com)

GitHub advisory

Affected versions

PackageAffectedFixed in
stripe-cli
Product
>= 1.11.1, < 1.21.31.21.3
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)

More Stripe advisories

All Stripe
Advisory
Smokescreen SSRF via deny list bypass (square brackets)
Medium5.3May 10, 2022
Smokescreen SSRF via deny list bypass
Medium5.8Apr 7, 2022
Vulnerability in Stripe CLI < 1.7.13
MediumMar 9, 2022
Vulnerability in Stripe for Visual Studio Code < 1.7.3
High7.5Mar 31, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.