← Back to browse · API

CVE-2025-53833

Severity
CRITICAL
CVSS
10.0
EPSS
0.09357
Risk score
43.27
CISA KEV
No
PoC
No
Published
2025-07-14
Modified
2025-07-15
First seen
2026-08-07
Aliases
EUVD-2025-21400, GHSA-JV7X-XHV2-P5V2
Products
saleem-hadad:larecipe < 2.8.1
Sources
euvd EUVD-2025-21400

Description

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration. Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.

References