CVE-2024-45401 - CVE House
Back to Database
Status published High CVE-2024-45401

stripe-cli Path Traversal vulnerability

Vulnerability Description

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45401

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stripe-cli
Vulnerable Versions:
>= 1.11.1, < 1.21.3

Timeline

Official Publish: September 5th, 2024
Last Modified: December 19th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)