MEDIUM6.8
GHSA-3965-hpx2-q597
Pug allows JavaScript code execution if an application accepts untrusted input
Quick fix
GHSA-3965-hpx2-q597 — pug-code-gen: upgrade to the fixed version with the command below.
npm install pug-code-gen@3.0.3Details
Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the `compileClient`, `compileFileClient`, or `compileClientWithDependenciesTracked` function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-36361[ADVISORY]
- https://github.com/pugjs/pug/pull/3428[WEB]
- https://github.com/pugjs/pug/pull/3438[WEB]
- https://github.com/pugjs/pug/commit/32acfe8f197dc44c54e8af32c7d7b19aa9d350fb[WEB]
- https://github.com/Coding-Competition-Team/hackac-2024/tree/main/web/pug[WEB]
- https://github.com/pugjs/pug[PACKAGE]
- https://github.com/pugjs/pug/blob/4767cafea0af3d3f935553df0f9a8a6e76d470c2/packages/pug/lib/index.js#L328[WEB]
- https://github.com/pugjs/pug/releases/tag/pug%403.0.3[WEB]
- https://pugjs.org/api/reference.html[WEB]
- https://www.npmjs.com/package/pug-code-gen[WEB]