VDB
Sign up
MEDIUM5.4

GHSA-55r9-7mf8-m382

Cross-site Scripting in edge.js

Quick fix

GHSA-55r9-7mf8-m382 — edge.js: upgrade to the fixed version with the command below.

npm install edge.js@5.3.2

Details

Edge is a logical and batteries included template engine for Node.js. This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if `{{ }}` are used.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/edge.js
Introduced in: 0Fixed in: 5.3.2
Fixnpm install edge.js@5.3.2

References