GHSA-p493-635q-r6gr
Remote code execution via the `pretty` option.
Quick fix
GHSA-p493-635q-r6gr — pug: upgrade to the fixed version with the command below.
npm install pug@3.0.1Details
### Impact
If a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend.
### Patches
Upgrade to `pug@3.0.1` or `pug-code-gen@3.0.2` or `pug-code-gen@2.0.3`, which correctly sanitise the parameter.
### Workarounds
If there is no way for un-trusted input to be passed to pug as the `pretty` option, e.g. if you compile templates in advance before applying user input to them, you do not need to upgrade.
### References
Original report: https://github.com/pugjs/pug/issues/3312
### For more information
If you believe you have found other vulnerabilities, please **DO NOT** open an issue. Instead, you can follow the instructions in our [Security Policy](https://github.com/pugjs/pug/blob/master/SECURITY.md)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pugjs/pug/security/advisories/GHSA-p493-635q-r6gr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21353[ADVISORY]
- https://github.com/pugjs/pug/issues/3312[WEB]
- https://github.com/pugjs/pug/pull/3314[WEB]
- https://github.com/pugjs/pug/commit/991e78f7c4220b2f8da042877c6f0ef5a4683be0[WEB]
- https://github.com/pugjs/pug/releases/tag/pug%403.0.1[WEB]
- https://www.npmjs.com/package/pug[WEB]
- https://www.npmjs.com/package/pug-code-gen[WEB]