VDB
Sign up
MEDIUM6.8

GHSA-3965-hpx2-q597

Pug allows JavaScript code execution if an application accepts untrusted input

Quick fix

GHSA-3965-hpx2-q597 — pug-code-gen: upgrade to the fixed version with the command below.

npm install pug-code-gen@3.0.3

Details

Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the `compileClient`, `compileFileClient`, or `compileClientWithDependenciesTracked` function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pug-code-gen
Introduced in: 0Fixed in: 3.0.3
Fixnpm install pug-code-gen@3.0.3
npm/pug
Introduced in: 0Fixed in: 3.0.3
Fixnpm install pug@3.0.3

References