remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
The vulnerability classified as CWE-123 (Write-what-where Condition) consists of insufficient path or input data validation during file write operations. An attacker can supply crafted input data, resulting in content being written to a path controlled by the attacker in the file system. This operation is possible remotely, without authentication and without user interaction.
An attacker can overwrite critical system or application files, which may lead to system integrity violation, malicious code execution (e.g., by injecting startup scripts or configurations), or permanent application damage (denial of service).
Patches available from the vendor should be applied according to the references. It is recommended to monitor the project repository at the address indicated in the references and update to a patched version immediately after its release.
remotion-dev remotion version v4.0.409
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H