GrapesJsBuilder File Upload allows all file uploads
Package
Affected versions
>= 4.0.0, < 4.4.18
>= 5.0.0, < 5.2.9
>= 6.0.0, < 6.0.7
Patched versions
4.4.18
5.2.9
6.0.7
Description
Published by the National Vulnerability Database
Dec 2, 2025
Published to the GitHub Advisory Database
Dec 2, 2025
Reviewed
Dec 2, 2025
Last updated
Dec 2, 2025
Summary
Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted.
Impact
If the media folder is not restricted from running files this can lead to a remote code execution.
References