VDB
Sign up
MEDIUM

GHSA-f7ph-p5rv-phw2

Cross-Site Scripting in nunjucks

Quick fix

GHSA-f7ph-p5rv-phw2 — nunjucks: upgrade to the fixed version with the command below.

npm install nunjucks@2.4.3

Details

Affected versions of `nunjucks` do not properly escape specially structured user input in template vars when in auto-escape mode, resulting in a cross-site scripting vulnerability.

## Proof of Concept

By using an array for the keys in a template var, escaping is bypassed. ```javascript name[]=<script>alert(1)</script> ```

A full PoC is available in the references section.

## Recommendation

Update to version 2.4.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nunjucks
Introduced in: 0Fixed in: 2.4.3
Fixnpm install nunjucks@2.4.3

References