Skip to content

ejs lacks certain pollution protection

Moderate
nxglabs published GHSA-wj32-jgc6-x7jp May 16, 2024

Package

npm ejs (npm)

Affected versions

< 3.1.10

Patched versions

3.1.10

Description

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits