MEDIUM
GHSA-f7ph-p5rv-phw2
Cross-Site Scripting in nunjucks
Quick fix
GHSA-f7ph-p5rv-phw2 — nunjucks: upgrade to the fixed version with the command below.
npm install nunjucks@2.4.3Details
Affected versions of `nunjucks` do not properly escape specially structured user input in template vars when in auto-escape mode, resulting in a cross-site scripting vulnerability.
## Proof of Concept
By using an array for the keys in a template var, escaping is bypassed. ```javascript name[]=<script>alert(1)</script> ```
A full PoC is available in the references section.
## Recommendation
Update to version 2.4.3 or later.
Are you affected?
Enter the version of the package you're using.