Description
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.4.2
References
Related Issues
- Arbitrary local file read vulnerability during template rendering - swig-templates - CVE-2023-25345
- Gatsby develop server has Local File Inclusion vulnerability - CVE-2023-34238
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- esbuild allows arbitrary file read when running the development server on Windows - Vulnerability
You might also like:
- Tags:
- npm
- swig
Anything's wrong? Let us know Last updated on March 20, 2023


