VDB
Sign up
CRITICAL9.8

GHSA-phwq-j96m-2c2q

ejs template injection vulnerability

Quick fix

GHSA-phwq-j96m-2c2q — ejs: upgrade to the fixed version with the command below.

npm install ejs@3.1.7

Details

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ejs
Introduced in: 0Fixed in: 3.1.7
Fixnpm install ejs@3.1.7

References