GHSA-p2fw-q3jr-jfj3CriticalCVSS 9.8
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the...
🔗 CVE IDs covered (1)
📋 Description
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file.